Executive brief
Budibase is a low-code platform used to build business applications and AI agents. A security flaw in how it links external chat accounts (like Slack or Discord) to Budibase users allows an attacker to trick a victim into linking the attacker's chat identity to the victim's account. If successful, the attacker can send messages to AI agents while impersonating the victim, potentially gaining access to sensitive data, knowledge sources, and administrative functions.
Technical details
A CSRF vulnerability exists in the Budibase AI chat-link handoff flow (`/api/chat-links/:instance/:token/handoff`). The application fails to implement CSRF protection or bind the confirmation token to a specific user session during the account-linking process. An attacker can generate a valid `confirmationToken` for their own external chat identity (Slack, Discord, etc.) and use phishing or a malicious site to trick an authenticated Budibase user into submitting a POST request to the confirmation endpoint. Because the backend binds the external identity to whichever user is currently authenticated during the POST request, the attacker gains the ability to interact with Budibase AI agents and automations using the victim's permissions. This is a same-tenant attack requiring user interaction.
Affected products
- Budibase Budibase <= 3.38.1
Timeline
- 2026-07-22: disclosed: Initial disclosure on GitHub Advisory Database
- 2026-07-24: advisory: Advisory updated