CVE-2026-48146 | budibase up to 3.38.x HTTP Call utils.ts fetchWithBlacklist server-side request forgery (GHSA-g6qx-g4pr-92v7)
A vulnerability marked as critical has been reported in budibase up to 3.38.x. This affects the function fetchWithBlacklist of the file packages/server/src/sdk/workspace/oauth2/utils.ts of the component HTTP Call Handler. Performing a manipulation results in server-side request forgery.
This vulnerability is cataloged as CVE-2026-48146. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.