Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. @budibase/server
  4. ›
  5. CVE-2026-48148

CVE-2026-48148: Budibase: Unvalidated VectorDB Host Parameter Enables SSRF

June 12, 2026

The VectorDB configuration endpoint in Budibase accepts a host parameter that undergoes no validation against internal IP ranges, reserved hostnames, or URL schemes. Any authenticated user with builder-level access can supply an arbitrary host value such as 169.254.169.254 or localhost, causing the server to initiate outbound TCP connections to internal network addresses or cloud metadata endpoints on their behalf.

References

  • github.com/Budibase/budibase/security/advisories/GHSA-cv96-5348-p5p8
  • github.com/advisories/GHSA-cv96-5348-p5p8
  • nvd.nist.gov/vuln/detail/CVE-2026-48148

Code Behaviors & Features

Detect and mitigate CVE-2026-48148 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 3.35.3

Fixed versions

  • 3.35.3

Solution

Upgrade to version 3.35.3 or above.

Impact 5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-918: Server-Side Request Forgery (SSRF)

Source file

npm/@budibase/server/CVE-2026-48148.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 13 Jun 2026 00:17:58 +0000.