Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. @budibase/server
  4. ›
  5. GHSA-gh4h-34gr-87r7

GHSA-gh4h-34gr-87r7: Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders

July 24, 2026

When an SSO-authenticated user tests an automation in the Budibase builder, their OAuth2 access token and refresh token are included in the automation test results. These results are broadcast via WebSocket to all builders connected to the same dev app and stored in an in-memory cache accessible to any builder who polls the test status endpoint. This allows any co-builder of the same app to steal the testing user’s OAuth2 tokens.

References

  • github.com/Budibase/budibase/commit/bca426de7dc36d680285295655dc640dea2aab21
  • github.com/Budibase/budibase/pull/19107
  • github.com/Budibase/budibase/releases/tag/3.39.25
  • github.com/Budibase/budibase/security/advisories/GHSA-gh4h-34gr-87r7
  • github.com/advisories/GHSA-gh4h-34gr-87r7

Code Behaviors & Features

Detect and mitigate GHSA-gh4h-34gr-87r7 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 3.38.1

Solution

Unfortunately, there is no solution available yet.

Impact 5.7 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Source file

npm/@budibase/server/GHSA-gh4h-34gr-87r7.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:18:52 +0000.