CVE-2026-33226 | budibase up to 3.30.6 /api/queries/preview server-side request forgery (GHSA-4647-wpjq-hh7f)
A vulnerability identified as critical has been detected in budibase up to 3.30.6. Affected is an unknown function of the file /api/queries/preview. Performing a manipulation results in server-side request forgery.
This vulnerability was named CVE-2026-33226. The attack may be initiated remotely. There is no available exploit.
It is recommended to apply a patch to fix this issue.