Executive brief
Budibase, a platform for building business applications, contains a vulnerability that allows unauthenticated attackers to steal credentials used for external data sources. By sending a specially crafted request to a public application, an attacker can force Budibase to send sensitive authentication tokens (like API keys) to a server they control. This could allow an attacker to impersonate the organization and access or modify data in third-party services connected to Budibase.
Technical details
A vulnerability in Budibase's REST integration component (`packages/server/src/integrations/rest.ts`) allows for credential exfiltration. The application attaches stored authentication headers (Bearer/Basic tokens and static headers) to outgoing requests before resolving the final URL. If a query path is manipulated via user-supplied parameters to include an absolute URL, Budibase ignores the configured base URL and sends the request—including the sensitive headers—to the attacker-specified host. This is exploitable by unauthenticated attackers if the affected query is published with the 'PUBLIC' role. This issue represents a bypass of a previous fix (GHSA-3gp5) because it lacks a same-origin check between the resolved request host and the datasource base host.
Affected products
- Budibase Budibase server <= 3.38.1
Timeline
- 2026-07-22: advisory: Initial GitHub Advisory published
- 2026-07-24: other: Advisory updated