Executive brief
Budibase Server is an open-source low-code platform used to build and deploy web applications. A server-side request forgery (SSRF) vulnerability in the query import feature allows authenticated users to make the application fetch content from arbitrary URLs, including internal cloud metadata services and restricted network resources, exposing sensitive configuration data and internal infrastructure details.
Technical details
The vulnerability exists in the query import endpoint (POST /api/queries/import/info) which calls fetchFromUrl() without validating user-supplied URLs. The function uses node-fetch to retrieve content from any URL scheme without checks for IP blacklisting, hostname resolution, or redirect restrictions, returning the full HTTP response body to the caller. Exploitation requires authentication and low privileges; an attacker can probe internal services (including cloud metadata endpoints like AWS/Azure/GCP) and retrieve sensitive information. The vulnerable code is in packages/server/src/api/controllers/query/import/index.ts (lines 74–91). A patch is available in version 3.41.3.
Affected products
- Budibase Server before 3.41.3
Timeline
- 2026-08-14: disclosed: GitHub security advisory published
- 2026-08-28: advisory: CVE-2026-82246 published
- 2026-08-14: patched: Fix available in version 3.41.3