THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-5fpj-28rv-84r7 (high) — Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist

[GHSA] GHSA-5fpj-28rv-84r7 (high) — Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist

highgithub_advisoriesPublished 2026-08-14

GHSA-5fpj-28rv-84r7 Severity: high CVE: CVE-2026-35219

Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist

## Summary

Budibase automation steps (outgoing webhook, Zapier, n8n, Slack, Discord, Make.com) make server-side HTTP requests to user-provided URLs using `node-fetch` directly, completely bypassing the IP blacklist protection that exists in the RES

Indicators of compromise

Original source: https://github.com/advisories/GHSA-5fpj-28rv-84r7