Vulnerability  ·  2026-10-03

Budibase AI table generation SSRF: raw node-fetch uploadUrl → cloud-metadata theft via LLM-generated attachment URLs (CVE-2026-103757)

VulnerabilityHigh impactGlobalCVE-2026-103757
NVD published CVE-2026-103757 (CVSS 7.7) on 2026-10-01: Budibase's AI table generation calls uploadUrl in packages/server/src/utilities/fileUtils.ts, which uses raw node-fetch instead of the fetchWithBlacklist guard used everywhere else. The SSRF is full-read: response bodies are saved to storage and URLs returned to the caller, enabling IAM credential theft from 169.254.169.254 and internal service scanning.
This is SSRF reached through the AI feature specifically: a user prompt causes the LLM to emit attacker-chosen URLs that the model-serving app then fetches without SSRF protection. It demonstrates the AI-data-plane → SSRF chain and gives cloud-credential theft from within an AI feature.
POST /api/ai/tables with a prompt that yields an attachment-column URL pointing at an internal address; processAttachments calls uploadUrl which uses raw node-fetch with no SSRF blacklist, fetches the internal URL, saves the response body to object storage, and returns the presigned URL to the attacker.
Budibase <= 3.41.0 (AI table generation + uploadUrl path)
Apply the fix replacing raw fetch with fetchWithBlacklist from @budibase/backend-core (Budibase advisory GHSA-3c52-v5v2-3r56; verify patched release); restrict builder access to trusted users.
Budibase advisory GHSA-3c52-v5v2-3r56NVD CVE-2026-103757
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →