Executive brief
Baserow is an open-source no-code platform for building databases and applications. An authentication flaw in the Application Builder allows unauthenticated users to access data sources and retrieve sensitive data that should be restricted based on user permissions. Attackers can enumerate data source identifiers and access rows and fields without proper credentials, exposing potentially confidential business information.
Technical details
The vulnerability is an authorization bypass in the Application Builder's data source dispatch mechanism. The dispatch and record-name views in backend/src/baserow/contrib/builder/api/data_sources/views.py are configured with a permissive permission class that allows unauthenticated callers. The DataSourceService.dispatch_data_sources method calls check_multiple_permissions but fails to pass raise_exception=True and does not examine the returned denial mapping, allowing execution to proceed regardless of permission check results. Since dispatched data sources run with the integration's own credentials, an unauthenticated attacker can request any data source by its integer identifier and receive the associated rows and fields. The fix (version 2.3.1) passes raise_exception to the permission check call, ensuring denied requests are properly rejected.
Affected products
- Baserow Baserow before 2.3.1
Timeline
- 2026-08-27: disclosed