CVE-2026-35219: Budibase: SSRF in automations reaches cloud metadata

HIGH CISA: TRACK*
Published August 17, 2026
CISO Take

Budibase's automation steps for outgoing webhooks, Zapier, n8n, Slack, and Discord call user-supplied URLs via node-fetch without the same BLACKLIST_IPS enforcement Budibase already applies to its REST integration, so any authenticated user can point an automation at internal services or the cloud metadata endpoint. This matters because Budibase is a low-code automation platform typically deployed with broad network reach into internal infrastructure, and a successful SSRF here can hand an attacker IAM credentials from the instance metadata service or access to internal-only APIs — a well-worn escalation path in cloud environments. There is no CISA KEV listing, no public exploit or Nuclei template, and no EPSS score yet, so this looks like a disclosed-but-not-yet-weaponized bug rather than an active campaign; the barrier to exploitation is simply having any authenticated Budibase account, which in many self-hosted deployments is a low bar. Patch to Budibase 3.41.3 now, and in the meantime egress-filter outbound traffic from the Budibase host/container (block 169.254.169.254 and RFC1918 ranges at the network layer) and audit automation configs for webhook/Slack/Discord/Zapier/n8n steps pointing at internal IPs or metadata addresses.

Sources: NVD GitHub Advisory ATLAS

What is the risk?

High severity given the impact (potential cloud credential theft via metadata service access or lateral movement to internal services), moderated by the requirement for an authenticated Budibase account — this is not unauthenticated remote exploitation. No CVSS vector, EPSS, or KEV data is published yet, and there's no public PoC or scanner template, so real-world exploitation likelihood is currently unproven but the technique (SSRF to cloud metadata) is well-known and trivially reproducible once an attacker has any valid login. Organizations self-hosting Budibase in cloud environments (AWS/GCP/Azure) with permissive IAM roles attached to the instance are at the highest risk; SaaS-hosted or tightly network-segmented deployments have a smaller blast radius.

How does the attack unfold?

Initial Access
An authenticated Budibase user configures an automation step (webhook, Zapier, n8n, Slack, or Discord) with a URL pointing at an internal service or cloud metadata endpoint.
AML.T0053
SSRF Exploitation
Budibase's server-side node-fetch call bypasses the BLACKLIST_IPS check applied elsewhere, letting the request reach internal infrastructure or 169.254.169.254.
AML.T0075
Credential Harvesting
The automation step's response, including any IAM credentials or internal data returned by the metadata service, is surfaced back to the attacker in the Budibase UI or logs.
AML.T0086
Impact
The attacker uses harvested cloud credentials or internal service access to pivot and escalate within the victim's cloud environment.
AML.T0112

What systems are affected?

Package Ecosystem Vulnerable Range Patched
budibase — — No patch

Do you use budibase? You're affected.

How severe is it?

CVSS 3.1
N/A
EPSS
0.5%
chance of exploitation in 30 days
Higher than 38% of all CVEs
Exploitation Status
Exploit Available
Exploitation: MEDIUM
Sophistication
Moderate
Exploitation Confidence
medium
○ CISA SSVC: Public PoC
Composite signal derived from CISA KEV, VulnCheck KEV, CISA SSVC, EPSS, Metasploit, Exploit-DB, trickest/cve, Nuclei templates, and inthewild.io exploitation reports.

What should I do?

1 step
  1. Upgrade to Budibase 3.41.3 or later immediately. Until patched, restrict which users can create/edit automations (least privilege on the builder role) and add network-layer egress controls blocking the Budibase host from reaching 169.254.169.254 and RFC1918/internal ranges except where explicitly required. Review IAM/instance-role permissions attached to the Budibase host or container and apply least privilege so metadata access has minimal blast radius even if reached. Audit existing automation configurations for webhook/Slack/Discord/Zapier/n8n steps with URLs pointing at internal hosts or metadata IPs, and monitor egress/proxy logs for requests to 169.254.169.254 or internal service ranges originating from the Budibase process.

What does CISA's SSVC say?

Decision Track*
Exploitation poc
Automatable No
Technical Impact partial

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

NIST AI RMF
GOVERN-6.1 - Third-party risk management for AI-enabled components
OWASP LLM Top 10
LLM07 - Insecure Plugin Design

Frequently Asked Questions

What is CVE-2026-35219?

Budibase's automation steps for outgoing webhooks, Zapier, n8n, Slack, and Discord call user-supplied URLs via node-fetch without the same BLACKLIST_IPS enforcement Budibase already applies to its REST integration, so any authenticated user can point an automation at internal services or the cloud metadata endpoint. This matters because Budibase is a low-code automation platform typically deployed with broad network reach into internal infrastructure, and a successful SSRF here can hand an attacker IAM credentials from the instance metadata service or access to internal-only APIs — a well-worn escalation path in cloud environments. There is no CISA KEV listing, no public exploit or Nuclei template, and no EPSS score yet, so this looks like a disclosed-but-not-yet-weaponized bug rather than an active campaign; the barrier to exploitation is simply having any authenticated Budibase account, which in many self-hosted deployments is a low bar. Patch to Budibase 3.41.3 now, and in the meantime egress-filter outbound traffic from the Budibase host/container (block 169.254.169.254 and RFC1918 ranges at the network layer) and audit automation configs for webhook/Slack/Discord/Zapier/n8n steps pointing at internal IPs or metadata addresses.

Is CVE-2026-35219 actively exploited?

No confirmed active exploitation of CVE-2026-35219 has been reported, but organizations should still patch proactively.

How to fix CVE-2026-35219?

Upgrade to Budibase 3.41.3 or later immediately. Until patched, restrict which users can create/edit automations (least privilege on the builder role) and add network-layer egress controls blocking the Budibase host from reaching 169.254.169.254 and RFC1918/internal ranges except where explicitly required. Review IAM/instance-role permissions attached to the Budibase host or container and apply least privilege so metadata access has minimal blast radius even if reached. Audit existing automation configurations for webhook/Slack/Discord/Zapier/n8n steps with URLs pointing at internal hosts or metadata IPs, and monitor egress/proxy logs for requests to 169.254.169.254 or internal service ranges originating from the Budibase process.

What systems are affected by CVE-2026-35219?

This vulnerability affects the following AI/ML architecture patterns: agent frameworks.

What is the CVSS score for CVE-2026-35219?

No CVSS score has been assigned yet.

What is the AI security impact?

Affected AI Architectures

agent frameworks

MITRE ATLAS Techniques

AML.T0053 AI Agent Tool Invocation
AML.T0075 Cloud Service Discovery
AML.T0086 Exfiltration via AI Agent Tool Invocation

Compliance Controls Affected

NIST AI RMF: GOVERN-6.1
OWASP LLM Top 10: LLM07

What are the technical details?

Original Advisory

Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps/outgoingWebhook.ts, packages/server/src/automations/steps/zapier.ts, packages/server/src/automations/steps/n8n.ts, packages/server/src/automations/steps/slack.ts, and packages/server/src/automations/steps/discord.ts use node-fetch on user-provided URLs without the BLACKLIST_IPS enforcement used by the REST integration, allowing an authenticated user to make server-side requests to cloud metadata and internal services. This issue is fixed in version 3.41.3.

Exploitation Scenario

An attacker with a low-privilege but authenticated Budibase account (e.g., a builder-role user in a self-hosted, cloud-deployed instance) creates or edits an automation and configures an outgoing webhook, Slack, Discord, n8n, or Zapier step with a target URL of http://169.254.169.254/latest/meta-data/iam/security-credentials/<role-name> instead of a legitimate endpoint. Because these steps use node-fetch directly without the BLACKLIST_IPS check, the Budibase server issues the request server-side and returns the response — including temporary IAM access keys — into the automation's output/logs, which the attacker can view in the UI. The attacker then uses the harvested cloud credentials to pivot into the broader AWS/GCP/Azure environment, escalating from a low-privilege app account to cloud infrastructure compromise.

Weaknesses (CWE)

CWE-918 — Server-Side Request Forgery (SSRF): The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Source: MITRE CWE corpus.

Timeline

Published
August 17, 2026
Last Modified
August 18, 2026
First Seen
August 18, 2026

Related Vulnerabilities