Junglewise Threat Intelligence

Budibase REST datasource credential theft via cross-origin leak

Severity: critical · CVSS 9.8 · Published 2026-07-24

Technologies: @budibase/server (npm), Budibase Server. Vendors: npm, Budibase.

Executive brief

Budibase, a platform for building business applications, contains a vulnerability that allows unauthenticated attackers to steal credentials used for external data sources. By sending a specially crafted request to a public application, an attacker can force Budibase to send sensitive authentication tokens (like API keys) to a server they control. This could allow an attacker to impersonate the organization and access or modify data in third-party services connected to Budibase.

Technical details

A vulnerability in Budibase's REST integration component (`packages/server/src/integrations/rest.ts`) allows for credential exfiltration. The application attaches stored authentication headers (Bearer/Basic tokens and static headers) to outgoing requests before resolving the final URL. If a query path is manipulated via user-supplied parameters to include an absolute URL, Budibase ignores the configured base URL and sends the request—including the sensitive headers—to the attacker-specified host. This is exploitable by unauthenticated attackers if the affected query is published with the 'PUBLIC' role. This issue represents a bypass of a previous fix (GHSA-3gp5) because it lacks a same-origin check between the resolved request host and the datasource base host.

Affected products

  • Budibase Budibase server <= 3.38.1

Timeline

  • 2026-07-22: advisory: Initial GitHub Advisory published
  • 2026-07-24: other: Advisory updated

References

Related threats