CVE-2026-35219: Budibase: SSRF in automations reaches cloud metadata
HIGH CISA: TRACK*Budibase's automation steps for outgoing webhooks, Zapier, n8n, Slack, and Discord call user-supplied URLs via node-fetch without the same BLACKLIST_IPS enforcement Budibase already applies to its REST integration, so any authenticated user can point an automation at internal services or the cloud metadata endpoint. This matters because Budibase is a low-code automation platform typically deployed with broad network reach into internal infrastructure, and a successful SSRF here can hand an attacker IAM credentials from the instance metadata service or access to internal-only APIs — a well-worn escalation path in cloud environments. There is no CISA KEV listing, no public exploit or Nuclei template, and no EPSS score yet, so this looks like a disclosed-but-not-yet-weaponized bug rather than an active campaign; the barrier to exploitation is simply having any authenticated Budibase account, which in many self-hosted deployments is a low bar. Patch to Budibase 3.41.3 now, and in the meantime egress-filter outbound traffic from the Budibase host/container (block 169.254.169.254 and RFC1918 ranges at the network layer) and audit automation configs for webhook/Slack/Discord/Zapier/n8n steps pointing at internal IPs or metadata addresses.
What is the risk?
High severity given the impact (potential cloud credential theft via metadata service access or lateral movement to internal services), moderated by the requirement for an authenticated Budibase account — this is not unauthenticated remote exploitation. No CVSS vector, EPSS, or KEV data is published yet, and there's no public PoC or scanner template, so real-world exploitation likelihood is currently unproven but the technique (SSRF to cloud metadata) is well-known and trivially reproducible once an attacker has any valid login. Organizations self-hosting Budibase in cloud environments (AWS/GCP/Azure) with permissive IAM roles attached to the instance are at the highest risk; SaaS-hosted or tightly network-segmented deployments have a smaller blast radius.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| budibase | — | — | No patch |
Do you use budibase? You're affected.
How severe is it?
What should I do?
1 step-
Upgrade to Budibase 3.41.3 or later immediately. Until patched, restrict which users can create/edit automations (least privilege on the builder role) and add network-layer egress controls blocking the Budibase host from reaching 169.254.169.254 and RFC1918/internal ranges except where explicitly required. Review IAM/instance-role permissions attached to the Budibase host or container and apply least privilege so metadata access has minimal blast radius even if reached. Audit existing automation configurations for webhook/Slack/Discord/Zapier/n8n steps with URLs pointing at internal hosts or metadata IPs, and monitor egress/proxy logs for requests to 169.254.169.254 or internal service ranges originating from the Budibase process.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-35219?
Budibase's automation steps for outgoing webhooks, Zapier, n8n, Slack, and Discord call user-supplied URLs via node-fetch without the same BLACKLIST_IPS enforcement Budibase already applies to its REST integration, so any authenticated user can point an automation at internal services or the cloud metadata endpoint. This matters because Budibase is a low-code automation platform typically deployed with broad network reach into internal infrastructure, and a successful SSRF here can hand an attacker IAM credentials from the instance metadata service or access to internal-only APIs — a well-worn escalation path in cloud environments. There is no CISA KEV listing, no public exploit or Nuclei template, and no EPSS score yet, so this looks like a disclosed-but-not-yet-weaponized bug rather than an active campaign; the barrier to exploitation is simply having any authenticated Budibase account, which in many self-hosted deployments is a low bar. Patch to Budibase 3.41.3 now, and in the meantime egress-filter outbound traffic from the Budibase host/container (block 169.254.169.254 and RFC1918 ranges at the network layer) and audit automation configs for webhook/Slack/Discord/Zapier/n8n steps pointing at internal IPs or metadata addresses.
Is CVE-2026-35219 actively exploited?
No confirmed active exploitation of CVE-2026-35219 has been reported, but organizations should still patch proactively.
How to fix CVE-2026-35219?
Upgrade to Budibase 3.41.3 or later immediately. Until patched, restrict which users can create/edit automations (least privilege on the builder role) and add network-layer egress controls blocking the Budibase host from reaching 169.254.169.254 and RFC1918/internal ranges except where explicitly required. Review IAM/instance-role permissions attached to the Budibase host or container and apply least privilege so metadata access has minimal blast radius even if reached. Audit existing automation configurations for webhook/Slack/Discord/Zapier/n8n steps with URLs pointing at internal hosts or metadata IPs, and monitor egress/proxy logs for requests to 169.254.169.254 or internal service ranges originating from the Budibase process.
What systems are affected by CVE-2026-35219?
This vulnerability affects the following AI/ML architecture patterns: agent frameworks.
What is the CVSS score for CVE-2026-35219?
No CVSS score has been assigned yet.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0053 AI Agent Tool Invocation AML.T0075 Cloud Service Discovery AML.T0086 Exfiltration via AI Agent Tool Invocation Compliance Controls Affected
What are the technical details?
Original Advisory
Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps/outgoingWebhook.ts, packages/server/src/automations/steps/zapier.ts, packages/server/src/automations/steps/n8n.ts, packages/server/src/automations/steps/slack.ts, and packages/server/src/automations/steps/discord.ts use node-fetch on user-provided URLs without the BLACKLIST_IPS enforcement used by the REST integration, allowing an authenticated user to make server-side requests to cloud metadata and internal services. This issue is fixed in version 3.41.3.
Exploitation Scenario
An attacker with a low-privilege but authenticated Budibase account (e.g., a builder-role user in a self-hosted, cloud-deployed instance) creates or edits an automation and configures an outgoing webhook, Slack, Discord, n8n, or Zapier step with a target URL of http://169.254.169.254/latest/meta-data/iam/security-credentials/<role-name> instead of a legitimate endpoint. Because these steps use node-fetch directly without the BLACKLIST_IPS check, the Budibase server issues the request server-side and returns the response — including temporary IAM access keys — into the automation's output/logs, which the attacker can view in the UI. The attacker then uses the harvested cloud credentials to pivot into the broader AWS/GCP/Azure environment, escalating from a low-privilege app account to cloud infrastructure compromise.
Weaknesses (CWE)
CWE-918 — Server-Side Request Forgery (SSRF): The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Source: MITRE CWE corpus.
References
- github.com/Budibase/budibase/commit/cc07563a6b0fc0f91c51aae295952b1295546a90 x_refsource_MISC
- github.com/Budibase/budibase/pull/19328 x_refsource_MISC
- github.com/Budibase/budibase/releases/tag/3.41.3 x_refsource_MISC
- github.com/Budibase/budibase/security/advisories/GHSA-5fpj-28rv-84r7 x_refsource_CONFIRM
Timeline
Related Vulnerabilities
CVE-2026-21858 10.0 n8n: Input Validation flaw enables exploitation
Same attack type: Data Extraction CVE-2025-53767 10.0 Azure OpenAI: SSRF EoP, no auth required (CVSS 10)
Same attack type: Data Extraction CVE-2023-3765 10.0 MLflow: path traversal allows arbitrary file read
Same attack type: Data Extraction CVE-2025-2828 10.0 LangChain RequestsToolkit: SSRF exposes cloud metadata
Same attack type: Data Extraction GHSA-vvpj-8cmc-gx39 10.0 picklescan: security flaw enables exploitation
Same attack type: Auth Bypass