Skip to content

Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`

High severity GitHub Reviewed Published Aug 14, 2026 in Budibase/budibase • Updated Aug 26, 2026

Package

npm @budibase/server (npm)

Affected versions

<= 3.38.1

Patched versions

None

Description

Summary

Budibase 3.39.7 allows a low-privilege authenticated published-app user with the built-in BASIC role to obtain arbitrary S3 pre-signed upload URLs backed by a workspace datasource's stored server-side credentials.

The affected endpoint is:

POST /api/attachments/:datasourceId/url

The caller can control:

bucket
key

and receives:

signedUrl
publicUrl

This lets a low-privilege published-app user mint S3 PUT URLs using server-side datasource credentials for attacker-chosen object destinations.

Steps:

  1. Log in as an admin user.
  2. Create a new app/workspace.
  3. In the development app context, create an S3 datasource with valid credentials.
  4. Publish the app.
  5. Create a low-privilege user with the built-in BASIC role on the published production app ID.
  6. Log in as that BASIC user.
  7. Send:
    POST /api/attachments/<datasourceId>/url

with:

{"bucket":"foo","key":"bar"}

and the published app header:

x-budibase-app-id: <published_app_id>

Observe a successful response containing:

signedUrl
publicUrl

Observed result

The following behavior:

dev BASIC request: 403 User does not have permission
app publish: SUCCESS
prod BASIC request: 200 OK
Example confirmed runtime values from the final successful run:

prodAppId: app_e6b4cdc6cd6949969a83ff11eee88c5a
datasourceId: datasource_0cec491b26a742468257c62382aa3284
publicUrl: https://foo.s3.eu-west-1.amazonaws.com/bar

The returned signedUrl contained standard AWS signing markers, including:

X-Amz-Credential=bb
X-Amz-Signature
X-Amz-Expires=900

Impact

A low-privilege published-app user who knows a valid datasource ID can mint S3 upload URLs backed by server-side datasource credentials and choose arbitrary destination bucket and key values.

Route definition

packages/server/src/api/routes/static.ts:45
Authorization logic
packages/server/src/middleware/authorized.ts
packages/server/src/middleware/resourceId.ts
Controller logic
packages/server/src/api/controllers/static/index.ts
Datasource lookup
packages/server/src/sdk/workspace/datasources/datasources.ts

References

@mjashanks mjashanks published to Budibase/budibase Aug 14, 2026
Published by the National Vulnerability Database Aug 17, 2026
Published to the GitHub Advisory Database Aug 26, 2026
Reviewed Aug 26, 2026
Last updated Aug 26, 2026

Severity

High

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
Low

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

EPSS score

Exploit Prediction Scoring System (EPSS)

This score estimates the probability of this vulnerability being exploited within the next 30 days. Data provided by FIRST.
(15th percentile)

Weaknesses

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action. Learn more on MITRE.

CVE ID

CVE-2026-54356

GHSA ID

GHSA-6x9p-4r67-5gjx

Source code

Credits

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.