<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T19:09:36.184951+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-322262</id>
    <title>EUVD-2026-322262</title>
    <updated>2026-10-10T19:09:36.236613+00:00</updated>
    <content>EUVD-2026-322262</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-322262"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45548</id>
    <title>fkie_cve-2026-45548</title>
    <updated>2026-10-10T19:09:36.236651+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Budibase is an open-source low-code platform. Prior to 3.34.8, the processUrlFile function in packages/server/src/automations/steps/ai/extract.ts uses fetch(fileUrl) directly without the IP blacklist validation that is consistently applied to all other automation steps. This allows an authenticated user to trigger server-side requests to internal network addresses. This vulnerability is fixed in 3.34.8.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45548"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rpj4-7x2v-wjrf</id>
    <title>GHSA-rpj4-7x2v-wjrf — Budibase: SSRF in AI Extract File Automation Step via Missing IP Blacklist Validation</title>
    <updated>2026-10-10T19:09:36.236686+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @budibase/server</p>
<p>## Vulnerability Details</p>
<p>**CWE-918**: Server-Side Request Forgery (SSRF)</p>
<p>The `processUrlFile` function in `packages/server/src/automations/steps/ai/extract.ts` uses `fetch(fileUrl)` directly **without the IP blacklist validation** that is consistently applied to all other automation steps. This allows an authenticated user to trigger server-side requests to internal network addresses.</p>
<p>### Vulnerable Code</p>
<p>**`packages/server/src/automations/steps/ai/extract.ts` (lines 116, 139)**:</p>
<p>```typescript
async function processUrlFile(fileUrl: string, ...): Promise&lt;ExtractInput&gt; {
  const response = await fetch(fileUrl)  // NO blacklist check!
  // ...
  const fallbackResponse = await fetch(fileUrl)  // Also NO blacklist check!
}
```</p>
<p>### Contrast with All Other Automation Steps (Same Codebase)</p>
<p>Every other automation step that makes outbound HTTP requests properly uses `fetchWithBlacklist`:</p>
<p>- `steps/slack.ts:19`: `response = await fetchWithBlacklist(url, {...})`
- `steps/discord.ts:28`: `response = await fetchWithBlacklist(url, {...})`
- `steps/zapier.ts:33`: `response = await fetchWithBlacklist(url, {...})`
- `steps/n8n.ts:53`: `response = await fetchWithBlacklist(url, request)`
- `steps/outgoingWebhook.ts`: `response = await fetchWithBlacklist(url, {...})`
- `steps/make.ts`: `response = await fetchWithBlacklist(url, {...})`</p>
<p>The `fetchWithBlacklist` function (`steps/utils.ts:100`) validates URLs against the IP blacklist which blocks:
- `127.0.0.0/8` (loopback)
- `10.0.0.0/8`, `1…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rpj4-7x2v-wjrf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1455</id>
    <title>WID-SEC-W-2026-1455 — Budibase: Schwachstelle ermöglicht Offenlegung von Informationen</title>
    <updated>2026-10-10T19:09:36.236746+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Budibase ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1455"/>
  </entry>
</feed>
