Executive brief
Budibase is a low-code platform that allows users to build internal applications by connecting to data sources via REST APIs. The REST datasource integration validates initial request URLs against a blacklist to prevent server-side request forgery attacks, but fails to validate HTTP redirects, allowing an attacker with builder-level access to bypass protections and access internal cloud metadata, credentials, and databases. This could lead to theft of cloud credentials and unauthorized access to internal services running alongside the Budibase instance.
Technical details
The vulnerability is a server-side request forgery (SSRF) bypass in the REST datasource integration (packages/server/src/integrations/rest.ts). Budibase validates the initial URL against an IP blacklist covering RFC 1918 private ranges, loopback, and link-local addresses; however, it fails to re-validate the target URL after HTTP redirects. The HTTP client (undici) is configured with default redirect handling ("follow" mode), so when an attacker configures a REST datasource pointing to an attacker-controlled server, that server can respond with a 302 redirect to a blacklisted internal address (e.g., http://169.254.169.254/latest/meta-data/), which is silently followed and the internal response is returned to the caller. The attack requires Builder role on the Budibase instance. The vulnerability was patched in version 3.38.1.
Affected products
- Budibase Budibase < 3.38.1
Timeline
- 2026-05-12: disclosed
- 2026-08-01: advisory: NVD published