CVE-2026-45548 | budibase up to 3.34.7 extract.ts processUrlFile server-side request forgery (EUVD-2026-32604)
A vulnerability was found in budibase up to 3.34.7. It has been classified as critical. This issue affects the function processUrlFile of the file packages/server/src/automations/steps/ai/extract.ts. This manipulation causes server-side request forgery.
The identification of this vulnerability is CVE-2026-45548. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.