CVE Explorer
CVE-2026-48146
Budibase is an open-source low-code platform. Prior to 3.39.0, the OAuth2 token fetch function in packages/server/src/sdk/workspace/oauth2/utils.ts uses raw fetch(config.url) with no SSRF protection. The safe wrapper fetchWithBlacklist() exists in the same codebase and is used in every other outbound HTTP call (automation steps, plugin downloads, object store), but was not applied to the OAuth2 token endpoint. A user with BUILDER role can point the OAuth2 token URL to internal services (CouchDB,
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"budibase","vendor":"Budibase","versions":[{"status":"affected","version":"< 3.39.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4604549f911f46d8666d1cbc029103b0fc77907a68d355b54cd5483d2dc5afb4 · sha256:cd0bbbaa454575c0… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.7,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:4604549f911f46d8666d1cbc029103b0fc77907a68d355b54cd5483d2dc5afb4 · sha256:cd0bbbaa454575c0… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-918","description":"CWE-918: Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4604549f911f46d8666d1cbc029103b0fc77907a68d355b54cd5483d2dc5afb4 · sha256:cd0bbbaa454575c0… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/Budibase/budibase/security/advisories/GHSA-g6qx-g4pr-92v7","tags":["x_refsource_CONFIRM"],"url":"https://github.com/Budibase/budibase/security/advisories/GHSA-g6qx-g4pr-92v7"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4604549f911f46d8666d1cbc029103b0fc77907a68d355b54cd5483d2dc5afb4 · sha256:cd0bbbaa454575c0… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/Budibase/budibase/security/advisories/GHSA-g6qx-g4pr-92v7"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4604549f911f46d8666d1cbc029103b0fc77907a68d355b54cd5483d2dc5afb4 · sha256:cd0bbbaa454575c0… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.