Budibase Server 在 3.41.3 版本之前存在一个服务器端请求伪造(SSRF)漏洞,位于查询导入端点。该端点在获取内容时未能对用户提供的 URL 进行充分验证。攻击者可以提交任意 URL,从而从内部服务(包括云元数据端点及其他受限制的网络资源)获取响应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82244 | 9.1 CRITICAL | Budibase before 3.41.3 Remote Code Execution via Plugin eval() |
| CVE-2026-82240 | 8.1 HIGH | Budibase before 3.41.3 Privilege Escalation via User Update API |
| CVE-2026-82245 | 8.1 HIGH | Budibase before 3.41.3 Missing Authorization License Management |
| CVE-2026-82239 | 8.1 HIGH | Budibase before 3.41.3 Authorization Bypass via datasources/query |
| CVE-2026-82242 | 7.7 HIGH | Budibase before 3.41.3 Cross-Application Resource Injection via Missing Authorization |
| CVE-2026-82243 | 7.6 HIGH | Budibase Server before 3.41.3 SSRF with Credential Leakage |
| CVE-2026-82241 | 7.1 HIGH | Budibase backend-core SSRF via incomplete default blacklist |
No comments yet