Skip to main content
HIGH

CVE-2026-103757

CVSS v3

7.7

HIGH

EPSS Score

—

exploit probability

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist. Authenticated builder users can send a prompt to POST /api/ai/tables that places an internal URL in an attachment column, causing the server to fetch it and return a presigned object-storage URL containing the response, such as cloud metadata credentials.

Technical details

CVSS v3 Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Published
2026-10-01
Last Modified
2026-10-01

Frequently asked questions

What is CVE-2026-103757?

Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist. Authenticated builder users can send a prompt to POST /api/ai/tables that places an internal URL in an attachment column, causing the server to fetch it and return a presigned object-storage URL containing the response, such as cloud metadata credentials.

Is CVE-2026-103757 actively exploited?

Active exploitation of CVE-2026-103757 has not been confirmed.

What is the CVSS score for CVE-2026-103757?

CVE-2026-103757 has a CVSS v3 base score of 7.7 (HIGH severity), with vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N.

Is CVE-2026-103757 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key