GHSA-hr66-5mqr-8mpx: Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
Summary
The Budibase Worker service exposes a public, unauthenticated API endpoint (GET /api/global/users/tenant/:id) that returns sensitive user information including tenantId, userId, email, and ssoId. The endpoint is registered in the PUBLIC_ENDPOINTS list with a TODO comment acknowledging it "should be an internal API." Any unauthenticated party can enumerate user emails or IDs to extract sensitive tenant and user metadata, enabling targeted attacks against multi-tenant deployments.
Details
Public endpoint registration at packages/worker/src/api/index.ts lines 56-59:
// TODO: This should be an internal api
{
route: "/api/global/users/tenant/:id",
method: "GET",
},
This endpoint is listed in PUBLIC_ENDPOINTS, which is passed to auth.buildAuthMiddleware(PUBLIC_ENDPOINTS) at line 154. When a request matches a public endpoint pattern, the authentication middleware sets ctx.publicEndpoint = true and calls next() without performing any authentication (verified at packages/backend-core/src/middleware/authenticated.ts lines 124-126, 249-251).
All subsequent middleware also skips for public endpoints:
- buildTenancyMiddleware — passes through
- activeTenant — passes through
- buildCsrfMiddleware — skipped for GET methods (line 48 of csrf.ts)
- The budibaseAccess gate at lines 160-168 explicitly returns next() when ctx.publicEndpoint is true
Route registration at packages/worker/src/api/routes/global/users.ts line 139:
loggedInRoutes
.get("/api/global/users/tenant/:id", controller.tenantUserLookup)
loggedInRoutes has no auth middleware group — it is created with endpointGroupList.group() (no middleware).
Handler implementation at packages/worker/src/api/controllers/global/users.ts lines 548-562:
export const tenantUserLookup = async (
ctx: UserCtx<void, LookupTenantUserResponse>
) => {
const id = ctx.params.id
// is email, check its valid
if (id.includes("@") && !emailValidator.validate(id)) {
ctx.throw(400, ${id} is not a valid email address to lookup.)
}
const
Details
Original advisory: https://github.com/advisories/GHSA-hr66-5mqr-8mpx
More from GitHub Security Advisories
- mediumGHSA-jr6p-8pjj-mfx6: Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators s…2026-07-31
- mediumGHSA-68cj-mvg9-rgm2: Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing…2026-07-31
- mediumGHSA-ff84-5f28-78qj: re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex`…2026-07-31
- mediumGHSA-6hxr-mr5r-9836: re2: Global `String.prototype.match` with an empty-matchable pattern never advances → inf…2026-07-31
- mediumGHSA-x83g-979r-f5fh: Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII2026-07-31