Budibase是英国Budibase公司开源的一个低代码应用开发平台。 Budibase 3.41.3之前版本存在服务端请求伪造漏洞,该漏洞源于自动化步骤对用户提供的URL使用node-fetch且未执行BLACKLIST_IPS限制,可能导致已认证用户向云元数据和内部服务发起服务端请求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-73410 | 8.5 HIGH | Budibase: SSRF via DNS rebinding in the REST datasource integration |
| CVE-2026-64657 | 8.4 HIGH | Budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL |
| CVE-2026-54356 | 7.1 HIGH | Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:data |
No comments yet