Executive brief
Baserow is an open-source database platform. A flaw in the admin impersonation feature allows API tokens to be generated for deactivated (inactive) users. While tokens are created, the deactivated user cannot actually use any API endpoints successfully, limiting practical exploitation. The vulnerability has been patched in version 2.3.3.
Technical details
The vulnerability exists in the BaserowImpersonateAuthTokenSerializer component within the admin users serializers module. An attacker with admin privileges can manipulate the serializer to generate authentication tokens for deactivated (non-staff, inactive) users through the admin impersonate endpoint. Although tokens are issued for inactive users, the underlying API endpoints enforce additional authorization checks that prevent token use, significantly limiting exploitation impact. The attack requires admin access and knowledge of the impersonation mechanism. The fix, released in version 2.3.3, prevents impersonation of deactivated users entirely.
Affected products
- Baserow Baserow up to 2.3.2
Timeline
- 2026-08-04: disclosed
- 2026-07-21: patched: Fix released in version 2.3.3