Junglewise Threat Intelligence

Budibase SSO OAuth2 token leakage in user metadata endpoints

Severity: medium · CVSS 4.9 · Published 2026-07-24

Technologies: @budibase/server (npm), Budibase @Budibase/Server. Vendors: npm, Budibase.

Executive brief

Budibase, a platform for building business applications, contained a vulnerability where sensitive login tokens were exposed to certain users. Users with the 'POWER' role could access the full profiles of other users, including secret OAuth2 access and refresh tokens used for Single Sign-On (SSO) through providers like Google or OIDC. An attacker with these tokens could potentially impersonate victims and access their external accounts or corporate data.

Technical details

The `/api/users/metadata` and `/api/users/metadata/:id` endpoints in `@budibase/server` fail to sanitize sensitive fields from user profile objects stored in CouchDB. While these endpoints are restricted to users with the POWER permission level, the returned JSON includes `oauth2.accessToken` and `oauth2.refreshToken` for SSO-authenticated users. The root cause is a lack of field stripping in the `processUser()` and `getRawGlobalUsers()` functions within the server's utility modules. An authenticated attacker with POWER privileges can retrieve these tokens to gain unauthorized access to the victim's identity provider resources (e.g., Google Workspace, Azure AD). The issue is fixed in version 3.39.25 by explicitly deleting sensitive SSO and profile fields before returning the response.

Affected products

  • Budibase @budibase/server < 3.39.25

Timeline

  • 2026-06-30: other: Fix pull request initiated
  • 2026-07-22: disclosed: Advisory published by Budibase
  • 2026-07-24: advisory: GitHub Advisory published

References

Related threats