Junglewise Threat Intelligence

CVE-2026-73407: Budibase REST datasource credential theft via cross-origin auth leak

CVE-2026-73407 · Severity: info · CVSS 9.8 · Published 2026-07-24

Technologies: @budibase/server (npm), Budibase. Vendors: npm, Budibase.

Executive brief

Budibase is a low-code platform that allows users to create data-driven applications using REST APIs as data sources. This vulnerability allows an unauthenticated attacker to steal stored API credentials (authentication tokens and static headers) by crafting a malicious query that redirects requests to an attacker-controlled server, exposing sensitive authentication secrets that are normally masked in the UI.

Technical details

The vulnerability is a credential leak in the REST datasource integration (packages/server/src/integrations/rest.ts). The root cause is that authentication headers and static headers are attached to outgoing HTTP requests before the destination URL is validated. The getUrl() function allows query paths starting with "http://" or "https://" to be treated as absolute URLs, or can be user-supplied via parameters like {{ t }}, bypassing the configured datasource base URL. No same-origin validation occurs between the resolved request host and the datasource's configured host before credentials are sent. Because queries can be published with PUBLIC role and execute under a minimal authorization check (QUERY, WRITE), an unauthenticated attacker can invoke the vulnerable endpoint POST /api/v2/queries/:queryId with a crafted parameter that redirects the request to an attacker-controlled server, where the credentials are sent in cleartext despite being masked elsewhere in the API. Patch available in version 3.40.0.

Affected products

  • Budibase Budibase <3.40.0

Timeline

  • 2026-07-22: disclosed
  • 2026-07-22: patched: Fixed in version 3.40.0

References

Related threats