What happened
NVD published CVE-2026-103757 (CVSS 7.7) on 2026-10-01: Budibase's AI table generation calls uploadUrl in packages/server/src/utilities/fileUtils.ts, which uses raw node-fetch instead of the fetchWithBlacklist guard used everywhere else. The SSRF is full-read: response bodies are saved to storage and URLs returned to the caller, enabling IAM credential theft from 169.254.169.254 and internal service scanning.
Why it matters
This is SSRF reached through the AI feature specifically: a user prompt causes the LLM to emit attacker-chosen URLs that the model-serving app then fetches without SSRF protection. It demonstrates the AI-data-plane → SSRF chain and gives cloud-credential theft from within an AI feature.
Attack vector
POST /api/ai/tables with a prompt that yields an attachment-column URL pointing at an internal address; processAttachments calls uploadUrl which uses raw node-fetch with no SSRF blacklist, fetches the internal URL, saves the response body to object storage, and returns the presigned URL to the attacker.
Affected systems
Budibase <= 3.41.0 (AI table generation + uploadUrl path)
Mitigation
Apply the fix replacing raw fetch with fetchWithBlacklist from @budibase/backend-core (Budibase advisory GHSA-3c52-v5v2-3r56; verify patched release); restrict builder access to trusted users.