PT-2026-51452 · Budibase · Budibase

·

CVE-2026-50132

·

Published

2026-06-22

·

Updated

2026-06-29

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Budibase versions 3.37.2 through 3.38.x
Description Budibase contains an issue where the GET /api/chat-links/:instance/:token/handoff endpoint is public and lacks authentication and Cross-Site Request Forgery (CSRF) protection. This allows an attacker to create a session token containing their own externalUserId and trick an authenticated user into visiting the URL. When the victim visits the link, their Budibase account is silently and permanently linked to the attacker's external chat identity (such as Slack, Discord, or MS Teams) without any consent UI. Consequently, the attacker can impersonate the victim to interact with AI agents, potentially gaining unauthorized access to sensitive data, reading table rows, and triggering automations with the victim's permissions.
Recommendations Update Budibase to version 3.39.0. As a temporary mitigation, restrict access to the GET /api/chat-links/:instance/:token/handoff endpoint.

Exploit

Fix

Improper Access Control

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50132
GHSA-V7J5-VC4M-723W

Affected Products

Budibase