Budibase 后端核心模块(@budibase/backend-core,被 @budibase/server 使用)在其用于 REST 数据源查询预览的默认 SSRF 黑名单(DEFAULT_BLACKLIST)中,遗漏了共享地址空间范围 100.64.0.0/10。当默认黑名单处于激活状态(即自托管部署未自定义 BLACKLIST_IPS)时,拥有“Builder”权限的已认证用户可以提交指向 100.64.0.0/10 网段内可达 HTTP(S) 服务的 REST 数据源查询预览请求,向 接口发起请求,导
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82244 | 9.1 CRITICAL | Budibase before 3.41.3 Remote Code Execution via Plugin eval() |
| CVE-2026-82240 | 8.1 HIGH | Budibase before 3.41.3 Privilege Escalation via User Update API |
| CVE-2026-82245 | 8.1 HIGH | Budibase before 3.41.3 Missing Authorization License Management |
| CVE-2026-82239 | 8.1 HIGH | Budibase before 3.41.3 Authorization Bypass via datasources/query |
| CVE-2026-82242 | 7.7 HIGH | Budibase before 3.41.3 Cross-Application Resource Injection via Missing Authorization |
| CVE-2026-82243 | 7.6 HIGH | Budibase Server before 3.41.3 SSRF with Credential Leakage |
| CVE-2026-82246 | 7.1 HIGH | Budibase Server before 3.41.3 SSRF via Query Import |
No comments yet