CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-hr66-5mqr-8mpx: Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint

highCVSS 7.5
Summary The Budibase Worker service exposes a public, unauthenticated API endpoint (GET /api/global/users/tenant/:id) that returns sensitive user information including tenantId, userId, email, and ssoId. The endpoint is registered in the PUBLIC_ENDPOINTS list with a TODO comment acknowledging it "should be an internal API." Any unauthenticated party can enumerate user emails or IDs to extract sensitive tenant and user metadata, enabling targeted attacks against multi-tenant deployments. Details Public endpoint registration at packages/worker/src/api/index.ts lines 56-59: // TODO: This should be an internal api { route: "/api/global/users/tenant/:id", method: "GET", }, This endpoint is listed in PUBLIC_ENDPOINTS, which is passed to auth.buildAuthMiddleware(PUBLIC_ENDPOINTS) at line 154. When a request matches a public endpoint pattern, the authentication middleware sets ctx.publicEndpoint = true and calls next() without performing any authentication (verified at packages/backend-core/src/middleware/authenticated.ts lines 124-126, 249-251). All subsequent middleware also skips for public endpoints: - buildTenancyMiddleware — passes through - activeTenant — passes through - buildCsrfMiddleware — skipped for GET methods (line 48 of csrf.ts) - The budibaseAccess gate at lines 160-168 explicitly returns next() when ctx.publicEndpoint is true Route registration at packages/worker/src/api/routes/global/users.ts line 139: loggedInRoutes .get("/api/global/users/tenant/:id", controller.tenantUserLookup) loggedInRoutes has no auth middleware group — it is created with endpointGroupList.group() (no middleware). Handler implementation at packages/worker/src/api/controllers/global/users.ts lines 548-562: export const tenantUserLookup = async ( ctx: UserCtx<void, LookupTenantUserResponse> ) => { const id = ctx.params.id // is email, check its valid if (id.includes("@") && !emailValidator.validate(id)) { ctx.throw(400, ${id} is not a valid email address to lookup.) } const

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
high — CVSS 7.5
Published
2026-07-24
Last updated
2026-07-24
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-hr66-5mqr-8mpx

More from GitHub Security Advisories