Executive brief
Budibase is a low-code application platform that stores backend database and cloud service credentials within its datasource configurations. Prior to version 3.40.0, the product fails to redact MongoDB connection strings and Firebase private keys from API responses, exposing live database credentials and Google Cloud service account keys in plaintext to any authenticated user with table read permissions.
Technical details
The vulnerability is a credential exposure flaw in the datasource secret redaction function (removeSecrets). The redaction logic masks PASSWORD and SENSITIVE_LONGFORM field types but overlooks credentials stored as STRING types—specifically MongoDB's connectionString field and Firebase's privateKey field. Attackers with table read permissions (a lower privilege bar than the intended builder-only access) can call the datasource read API endpoint (GET /api/datasources/:datasourceId) to retrieve plaintext connection URIs containing database credentials and unencrypted Firebase service account private keys. The root cause is incomplete field-type coverage in the redaction schema. The vulnerability has been patched in Budibase 3.40.0 and later.
Affected products
- Budibase Budibase before 3.40.0
Timeline
- 2026-07-22: disclosed
- 2026-08-13: advisory
- 2026-08-13: patched: version 3.40.0