CVE-2026-48148 | budibase up to 3.35.2 VectorDB Configuration Endpoint host server-side request forgery (GHSA-cv96-5348-p5p8)
A vulnerability classified as critical has been found in budibase up to 3.35.2. This issue affects some unknown processing of the component VectorDB Configuration Endpoint. The manipulation of the argument host leads to server-side request forgery.
This vulnerability is documented as CVE-2026-48148. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.