<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:11:40.896445+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-322418</id>
    <title>EUVD-2026-322418</title>
    <updated>2026-10-03T21:11:40.899013+00:00</updated>
    <content>EUVD-2026-322418</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-322418"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48146</id>
    <title>fkie_cve-2026-48146</title>
    <updated>2026-10-03T21:11:40.899049+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Budibase is an open-source low-code platform. Prior to 3.39.0, the OAuth2 token fetch function in packages/server/src/sdk/workspace/oauth2/utils.ts uses raw fetch(config.url) with no SSRF protection. The safe wrapper fetchWithBlacklist() exists in the same codebase and is used in every other outbound HTTP call (automation steps, plugin downloads, object store), but was not applied to the OAuth2 token endpoint. A user with BUILDER role can point the OAuth2 token URL to internal services (CouchDB, cloud metadata) to exfiltrate sensitive data. This vulnerability is fixed in 3.39.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48146"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g6qx-g4pr-92v7</id>
    <title>GHSA-g6qx-g4pr-92v7 — Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection</title>
    <updated>2026-10-03T21:11:40.899083+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @budibase/server</p>
<p>### Summary</p>
<p>The OAuth2 token fetch function in `packages/server/src/sdk/workspace/oauth2/utils.ts` (line 59) uses raw `fetch(config.url)` with **no SSRF protection**. The safe wrapper `fetchWithBlacklist()` exists in the same codebase and is used in every other outbound HTTP call (automation steps, plugin downloads, object store), but was **not applied** to the OAuth2 token endpoint.</p>
<p>A user with BUILDER role can point the OAuth2 token URL to internal services (CouchDB, cloud metadata) to exfiltrate sensitive data.</p>
<p>### Details</p>
<p>**Vulnerable code — `packages/server/src/sdk/workspace/oauth2/utils.ts:59`:**</p>
<p>```typescript
async function fetchToken(config: OAuth2Config): Promise&lt;TokenResponse&gt; {
  // ...
  const response = await fetch(config.url, fetchConfig)  // NO blacklist check!
  // ...
}
```</p>
<p>**Safe wrapper used everywhere else — `packages/backend-core/src/utils/outboundFetch.ts`:**</p>
<p>```typescript
export async function fetchWithBlacklist(url: string, opts?: RequestInit) {
  await blacklist.isBlacklisted(url)  // Checks against internal IPs
  const response = await fetch(url, { ...opts, redirect: "manual" })
  // Re-checks every redirect target
}
```</p>
<p>**Where `fetchWithBlacklist` IS used (consistency gap proof):**
- `automations/steps/discord.ts` — Discord webhook
- `automations/steps/slack.ts` — Slack webhook
- `automations/steps/make.ts` — Make.com integration
- `automations/steps/n8n.ts` — n8n integration
- `automations/steps/zapier.ts` — Zapier integration
- `automati…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g6qx-g4pr-92v7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1629</id>
    <title>WID-SEC-W-2026-1629 — Budibase: Mehrere Schwachstellen</title>
    <updated>2026-10-03T21:11:40.899145+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Budibase ausnutzen, um Administratorrechte zu erlangen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1629"/>
  </entry>
</feed>
