A AegiFlow
MEDIUMCVSS 4.9

CVE-2026-73304

CVE-2026-73304 updated by NVD

Published
2026-07-24
Modified
2026-09-10
Sources
github-advisory, nvd

Summary

Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id returned user objects processed by packages/server/src/utilities/global.ts without removing oauth2.accessToken or oauth2.refreshToken. A user with the POWER role could retrieve the identity-provider credentials of SSO-authenticated users and use the refresh tokens for persistent access to connected services. This issue is fixed in version 3.39.25.

Affected packages

EcosystemPackageAffected versionsFixed versions
npm@budibase/server3.39.25

Remediation: Upgrade to 3.39.25 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.