<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 18:07:14 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-322262</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322262</link>
      <description>EUVD-2026-322262</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322262</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45548</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45548</link>
      <description>&lt;p&gt;Budibase is an open-source low-code platform. Prior to 3.34.8, the processUrlFile function in packages/server/src/automations/steps/ai/extract.ts uses fetch(fileUrl) directly without the IP blacklist validation that is consistently applied to all other automation steps. This allows an authenticated user to trigger server-side requests to internal network addresses. This vulnerability is fixed in 3.34.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Budibase is an open-source low-code platform. Prior to 3.34.8, the processUrlFile function in packages/server/src/automations/steps/ai/extract.ts uses fetch(fileUrl) directly without the IP blacklist validation that is consistently applied to all other automation steps. This allows an authenticated user to trigger server-side requests to internal network addresses. This vulnerability is fixed in 3.34.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45548</guid>
    </item>
    <item>
      <title>GHSA-rpj4-7x2v-wjrf — Budibase: SSRF in AI Extract File Automation Step via Missing IP Blacklist Validation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rpj4-7x2v-wjrf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @budibase/server&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;**CWE-918**: Server-Side Request Forgery (SSRF)&lt;/p&gt;
&lt;p&gt;The `processUrlFile` function in `packages/server/src/automations/steps/ai/extract.ts` uses `fetch(fileUrl)` directly **without the IP blacklist validation** that is consistently applied to all other automation steps. This allows an authenticated user to trigger server-side requests to internal network addresses.&lt;/p&gt;
&lt;p&gt;### Vulnerable Code&lt;/p&gt;
&lt;p&gt;**`packages/server/src/automations/steps/ai/extract.ts` (lines 116, 139)**:&lt;/p&gt;
&lt;p&gt;```typescript
async function processUrlFile(fileUrl: string, ...): Promise&amp;lt;ExtractInput&amp;gt; {
  const response = await fetch(fileUrl)  // NO blacklist check!
  // ...
  const fallbackResponse = await fetch(fileUrl)  // Also NO blacklist check!
}
```&lt;/p&gt;
&lt;p&gt;### Contrast with All Other Automation Steps (Same Codebase)&lt;/p&gt;
&lt;p&gt;Every other automation step that makes outbound HTTP requests properly uses `fetchWithBlacklist`:&lt;/p&gt;
&lt;p&gt;- `steps/slack.ts:19`: `response = await fetchWithBlacklist(url, {...})`
- `steps/discord.ts:28`: `response = await fetchWithBlacklist(url, {...})`
- `steps/zapier.ts:33`: `response = await fetchWithBlacklist(url, {...})`
- `steps/n8n.ts:53`: `response = await fetchWithBlacklist(url, request)`
- `steps/outgoingWebhook.ts`: `response = await fetchWithBlacklist(url, {...})`
- `steps/make.ts`: `response = await fetchWithBlacklist(url, {...})`&lt;/p&gt;
&lt;p&gt;The `fetchWithBlacklist` function (`steps/utils.ts:100`) validates URLs against the IP blacklist which blocks:
- `127.0.0.0/8` (loopback)
- `10.0.0.0/8`, `1…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @budibase/server&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;**CWE-918**: Server-Side Request Forgery (SSRF)&lt;/p&gt;
&lt;p&gt;The `processUrlFile` function in `packages/server/src/automations/steps/ai/extract.ts` uses `fetch(fileUrl)` directly **without the IP blacklist validation** that is consistently applied to all other automation steps. This allows an authenticated user to trigger server-side requests to internal network addresses.&lt;/p&gt;
&lt;p&gt;### Vulnerable Code&lt;/p&gt;
&lt;p&gt;**`packages/server/src/automations/steps/ai/extract.ts` (lines 116, 139)**:&lt;/p&gt;
&lt;p&gt;```typescript
async function processUrlFile(fileUrl: string, ...): Promise&amp;lt;ExtractInput&amp;gt; {
  const response = await fetch(fileUrl)  // NO blacklist check!
  // ...
  const fallbackResponse = await fetch(fileUrl)  // Also NO blacklist check!
}
```&lt;/p&gt;
&lt;p&gt;### Contrast with All Other Automation Steps (Same Codebase)&lt;/p&gt;
&lt;p&gt;Every other automation step that makes outbound HTTP requests properly uses `fetchWithBlacklist`:&lt;/p&gt;
&lt;p&gt;- `steps/slack.ts:19`: `response = await fetchWithBlacklist(url, {...})`
- `steps/discord.ts:28`: `response = await fetchWithBlacklist(url, {...})`
- `steps/zapier.ts:33`: `response = await fetchWithBlacklist(url, {...})`
- `steps/n8n.ts:53`: `response = await fetchWithBlacklist(url, request)`
- `steps/outgoingWebhook.ts`: `response = await fetchWithBlacklist(url, {...})`
- `steps/make.ts`: `response = await fetchWithBlacklist(url, {...})`&lt;/p&gt;
&lt;p&gt;The `fetchWithBlacklist` function (`steps/utils.ts:100`) validates URLs against the IP blacklist which blocks:
- `127.0.0.0/8` (loopback)
- `10.0.0.0/8`, `1…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rpj4-7x2v-wjrf</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1455 — Budibase: Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1455</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Budibase ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Budibase ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1455</guid>
    </item>
  </channel>
</rss>
