THREAT OPS › Threat News › [GHSA] GHSA-5fpj-28rv-84r7 (high) — Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist
[GHSA] GHSA-5fpj-28rv-84r7 (high) — Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist
GHSA-5fpj-28rv-84r7 Severity: high CVE: CVE-2026-35219
Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist
## Summary
Budibase automation steps (outgoing webhook, Zapier, n8n, Slack, Discord, Make.com) make server-side HTTP requests to user-provided URLs using `node-fetch` directly, completely bypassing the IP blacklist protection that exists in the RES
Indicators of compromise
- CVE-2026-35219cve
- http://169.254.169.254/latest/meta-data/`url
- 127.0.0.0/8cidr
- 10.0.0.0/8cidr
- 172.16.0.0/12cidr
- 192.168.0.0/16cidr
- 169.254.0.0/16cidr
- make.comdomain
Original source: https://github.com/advisories/GHSA-5fpj-28rv-84r7