5.7
CVE-2026-73308
- EPSS 0.29%
- Veröffentlicht 12.08.2026 19:01:15
- Zuletzt bearbeitet 14.08.2026 22:17:10
- CVE-Watchlists
- Unerledigt
Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders
Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts returned automation test results containing trigger.outputs.user.oauth2, broadcast BuilderSocketEvent.AutomationTestProgress to the app room, and stored progress in packages/server/src/automations/testProgress.ts without user scoping. A co-builder could receive or poll another SSO-authenticated builder test and obtain OAuth2 access and refresh tokens. The fix adds sanitizeAutomationTestResult and isolates progress by user. This issue is fixed in version 3.39.25.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerBudibase
≫
Produkt
budibase
Version
< 3.39.25
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.217 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.7 | 2.1 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://github.com/Budibase/budibase/releases/tag/3.39.25
https://github.com/Budibase/budibase/security/advisories/GHSA-gh4h-34gr-87r7
https://github.com/Budibase/budibase/pull/19107
https://github.com/Budibase/budibase/commit/bca426de7dc36d680285295655dc640dea2aab21