A server-side request forgery flaw tracked as CVE-2026-48153 was disclosed in Budibase, allowing an authenticated user with builder-role access to abuse the platform's OAuth2 data source configuration and force the backend to send requests to attacker-controlled or internal endpoints. The issue stems from loose Joi URI validation in the Token Endpoint field for a mock OAuth2 data source, enabling requests to internal services such as AWS Instance Metadata Service at 169.254.169.254. When the OAuth authentication flow is triggered, the backend issues a POST request to the supplied endpoint and may expose the response through logs, the client interface, or workspace context, creating a path to credential theft and internal network reconnaissance.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
A GitHub pull request documented work to add an auxiliary Metasploit module for CVE-2026-45430, a Backdrop CMS Salesforce CSRF issue. The discussion also shows the item being moved into the Metasploit Kanban board's Todo state.
The vulnerability report states that the fix for CVE-2026-48153 adds blacklist validation and routes outbound requests through a safeFetch wrapper. The same report also notes a suggested mitigation of blocking outbound access to 169.254.169.254 at the network level.
A server-side request forgery vulnerability affecting Budibase's OAuth2 SDK was disclosed as CVE-2026-48153. The issue allows an authenticated builder-role user to direct the backend to attacker-specified internal endpoints, including cloud metadata services, during the OAuth token flow.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.