GHSA-6x9p-4r67-5gjx: High severity npm/@budibase/server vulnerability

Published Aug 26, 2026
·
Updated

Summary Budibase 3.39.7 allows a low-privilege authenticated published-app user with the built-in BASIC role to obtain arbitrary S3 pre-signed upload URLs backed by a workspace datasource's stored server-side credentials.

The affected endpoint is:

POST /api/attachments/:datasourceId/url

The caller can control: text bucket key and receives: text signedUrl publicUrl

This lets a low-privilege published-app user mint S3 PUT URLs using server-side datasource credentials for attacker-chosen object destinations.

Steps:

1. Log in as an admin user. 2. Create a new app/workspace. 3. In the development app context, create an S3 datasource with valid credentials. 4. Publish the app. 5. Create a low-privilege user with the built-in BASIC role on the published production app ID. 6. Log in as that BASIC user. 7. Send: POST /api/attachments/<datasourceId>/url

with: json {"bucket":"foo","key":"bar"} and the published app header: text x-budibase-app-id: <publishedappid> Observe a successful response containing: text signedUrl publicUrl

Observed result

The following behavior:

dev BASIC request: 403 User does not have permission app publish: SUCCESS prod BASIC request: 200 OK Example confirmed runtime values from the final successful run: text prodAppId: appe6b4cdc6cd6949969a83ff11eee88c5a datasourceId: datasource0cec491b26a742468257c62382aa3284 publicUrl: https://foo.s3.eu-west-1.amazonaws.com/bar The returned signedUrl contained standard AWS signing markers, including: text X-Amz-Credential=bb X-Amz-Signature X-Amz-Expires=900 Impact

A low-privilege published-app user who knows a valid datasource ID can mint S3 upload URLs backed by server-side datasource credentials and choose arbitrary destination bucket and key values.

Route definition packages/server/src/api/routes/static.ts:45 Authorization logic packages/server/src/middleware/authorized.ts packages/server/src/middleware/resourceId.ts Controller logic packages/server/src/api/controllers/static/index.ts Datasource lookup packages/server/src/sdk/workspace/datasources/datasources.ts

Affected Software

1 affected component
npm/@budibase/server<=3.38.1

Event History

Aug 26, 2026
Advisory Published
via GitHub·02:07 PM
Data Sourced
via GitHub·02:07 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which users are exposed to this issue?

Low-privilege authenticated users assigned the built-in BASIC role on a published production app are exposed when that app has access to an S3 datasource with valid stored credentials. The observed development-app BASIC request was denied, while the published-app request succeeded.

2

What does an attacker need to exploit it?

The attacker needs to authenticate as a BASIC user for the published app and send a POST request to /api/attachments/:datasourceId/url with the published app ID in the x-budibase-app-id header. They can supply the bucket and key values used to generate the upload URL.

3

How can I confirm whether a published app is affected?

Using a BASIC-role account for the published app, request POST /api/attachments/<datasourceId>/url with a bucket and key in the request body and the published app ID header. A successful response containing signedUrl and publicUrl indicates that the account can mint S3 PUT URLs through the datasource credentials.

4

What access can the resulting URL provide?

The response provides an S3 pre-signed URL for a PUT operation, using the workspace datasource's server-side credentials. The object destination is attacker-controlled through the supplied bucket and key values.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203