Budibase disclosed two high-severity vulnerabilities affecting its low-code platform, including an unrestricted server-side request forgery tracked as CVE-2026-33226 and a stored cross-site scripting flaw tracked as CVE-2026-35218. The SSRF issue affects version 3.30.6 and earlier in the REST datasource query preview endpoint, POST /api/queries/preview, where an authenticated admin can supply an arbitrary URL in fields.path and force the server to make unvalidated HTTP requests. That behavior can expose internal-only resources such as cloud metadata endpoints, internal databases, Kubernetes APIs, and other internal network services, with reported risk of OAuth2 token theft and potentially full Google Cloud access in some GCP deployments.
The second flaw affects versions prior to 3.32.5 and stems from unsanitized entity names rendered with Svelte's {@html} directive in the Builder Command Palette. An authenticated user with Builder access can inject malicious HTML into names for tables, views, queries, or automations, and the payload executes when another Builder-role user opens the palette with Ctrl+K, enabling session cookie theft and possible full account takeover. Budibase patched the stored XSS issue in version 3.32.5, while no public patch was available for the SSRF issue at the time of publication.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Budibase disclosed CVE-2026-35218, a stored cross-site scripting vulnerability affecting versions prior to 3.32.5 in which unsanitized entity names were rendered in the Builder Command Palette. The company fixed the issue in version 3.32.5; successful exploitation could enable session theft and full account takeover for Builder-role users.
Budibase disclosed CVE-2026-33226, an unrestricted server-side request forgery flaw in the REST datasource query preview endpoint affecting version 3.30.6 and earlier. The issue could let an authenticated admin trigger arbitrary server-side HTTP requests and potentially access internal services or steal GCP OAuth2 tokens; no public patch was available at disclosure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.