Executive brief
Budibase is a platform used to build business applications and automations. A security flaw allowed users with 'builder' permissions to steal the OAuth2 login tokens of other builders working on the same application. This could allow an attacker to access the victim's connected external accounts, such as Google Workspace, GitHub, or Azure AD, even after the victim has logged out.
Technical details
An information disclosure vulnerability exists in Budibase's automation testing pipeline. When a builder tests an automation, the `getUserContextBindings` function includes sensitive OAuth2 access and refresh tokens in the user context. These tokens are then included in the automation's trigger outputs and broadcast via WebSockets to all other builders connected to the same application room. Additionally, the results are stored in an in-memory cache that can be polled via the `/api/automations/:id/test/status` endpoint without proper user isolation. An attacker with builder-level access can passively or actively intercept these tokens to gain unauthorized access to external service integrations. The issue is fixed in version 3.40.0 by sanitizing test results before broadcast and storage.
Affected products
- Budibase @budibase/server < 3.40.0
Timeline
- 2026-07-22: disclosed
- 2026-07-24: advisory: GitHub Advisory published
- 2026-07-24: patched
References
- https://github.com/Budibase/budibase/security/advisories/GHSA-gh4h-34gr-87r7
- https://github.com/Budibase/budibase/pull/19107
- https://github.com/Budibase/budibase/commit/bca426de7dc36d680285295655dc640dea2aab21
- https://github.com/Budibase/budibase/releases/tag/3.39.25
- https://api.github.com/repos/Budibase/budibase/security-advisories/GHSA-gh4h-34gr-87r7