PT-2026-71906 · Budibase · Budibase
CVSS v4.0
8.7
High
| Vector | AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Budibase versions prior to 3.40.0
Description
A cross-site request forgery (CSRF) issue exists in the 'chat-link handoff' endpoint. This allows an attacker to bind an external chat identity to a victim's account by crafting a phishing page that automatically submits a POST request containing a leaked confirmation token. Successful exploitation enables the attacker to impersonate the victim within agent operations and inherit their permissions.
Recommendations
Update to version 3.40.0 or later.
Exploit
Fix
Improper Authorization
Insufficient Verification of Data Authenticity
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Budibase