CyberRota Analysis
AI-GeneratedBudibase versions up to 3.41.0 are vulnerable to a server-side request forgery (SSRF) flaw in the AI table generation feature, allowing authenticated builder users to exploit the uploadUrl function. This vulnerability can lead to the exposure of sensitive internal URLs and presigned object-storage URLs, potentially revealing cloud metadata credentials. Organizations using Budibase should prioritize patching this vulnerability to mitigate the risk of unauthorized access to sensitive data.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist. Authenticated builder users can send a prompt to POST /api/ai/tables that places an internal URL in an attachment column, causing the server to fetch it and return a presigned object-storage URL containing the response, such as cloud metadata credentials.