Insecure Default Initialization of Resource Affecting @budibase/backend-core package, versions <3.33.4


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.01% (2nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-BUDIBASEBACKENDCORE-15917492
  • published6 Apr 2026
  • disclosed3 Apr 2026
  • creditMoonster8282

Introduced: 3 Apr 2026

NewCVE-2026-31818  (opens in a new tab)
CWE-1188  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade @budibase/backend-core to version 3.33.4 or higher.

Overview

@budibase/backend-core is a Budibase backend core libraries used in server and worker

Affected versions of this package are vulnerable to Insecure Default Initialization of Resource via the isBlacklisted function when the BLACKLIST_IPS environment variable is unset, causing the blacklist check to always return false and allowing unrestricted outbound requests from the server to arbitrary internal or external network locations. An attacker with low privileges can access sensitive internal services and exfiltrate confidential data, modify or delete records, and potentially disrupt service operation by creating malicious REST datasources and executing queries targeting internal infrastructure.

CVSS Base Scores

version 4.0
version 3.1