{"id":"GHSA-6x9p-4r67-5gjx","summary":"Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`","details":"### Summary\nBudibase 3.39.7 allows a low-privilege authenticated published-app user with the built-in BASIC role to obtain arbitrary S3 pre-signed upload URLs backed by a workspace datasource's stored server-side credentials.\n\nThe affected endpoint is:\n\n`POST /api/attachments/:datasourceId/url`\n\nThe caller can control:\n```text\nbucket\nkey\n```\nand receives:\n```text\nsignedUrl\npublicUrl\n```\n\nThis lets a low-privilege published-app user mint S3 `PUT` URLs using server-side datasource credentials for attacker-chosen object destinations.\n\nSteps:\n\n1. Log in as an admin user.\n2. Create a new app/workspace.\n3. In the development app context, create an S3 datasource with valid credentials.\n4. Publish the app.\n5. Create a low-privilege user with the built-in BASIC role on the published production app ID.\n6. Log in as that BASIC user.\n7. Send:\n`POST /api/attachments/\u003cdatasourceId\u003e/url`\n\nwith:\n```json\n{\"bucket\":\"foo\",\"key\":\"bar\"}\n```\nand the published app header:\n```text\nx-budibase-app-id: \u003cpublished_app_id\u003e\n```\nObserve a successful response containing:\n```text\nsignedUrl\npublicUrl\n```\n\n### Observed result\n\nThe following behavior:\n\ndev BASIC request: 403 User does not have permission\napp publish: SUCCESS\nprod BASIC request: 200 OK\nExample confirmed runtime values from the final successful run:\n```text\nprodAppId: app_e6b4cdc6cd6949969a83ff11eee88c5a\ndatasourceId: datasource_0cec491b26a742468257c62382aa3284\npublicUrl: https://foo.s3.eu-west-1.amazonaws.com/bar\n```\nThe returned signedUrl contained standard AWS signing markers, including:\n```text\nX-Amz-Credential=bb\nX-Amz-Signature\nX-Amz-Expires=900\n```\n### Impact\n\nA low-privilege published-app user who knows a valid datasource ID can mint S3 upload URLs backed by server-side datasource credentials and choose arbitrary destination bucket and key values.\n\n### Route definition\n`packages/server/src/api/routes/static.ts:45`\nAuthorization logic\n`packages/server/src/middleware/authorized.ts`\n`packages/server/src/middleware/resourceId.ts`\nController logic\n`packages/server/src/api/controllers/static/index.ts`\nDatasource lookup\n`packages/server/src/sdk/workspace/datasources/datasources.ts`","aliases":["CVE-2026-54356"],"modified":"2026-08-26T14:15:08.194881760Z","published":"2026-08-26T14:07:26Z","database_specific":{"nvd_published_at":"2026-08-17T21:16:46Z","cwe_ids":["CWE-862"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-08-26T14:07:26Z"},"references":[{"type":"WEB","url":"https://github.com/Budibase/budibase/security/advisories/GHSA-6x9p-4r67-5gjx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54356"},{"type":"PACKAGE","url":"https://github.com/Budibase/budibase"},{"type":"WEB","url":"https://github.com/Budibase/budibase/releases/tag/3.41.3"}],"affected":[{"package":{"name":"@budibase/server","ecosystem":"npm","purl":"pkg:npm/%40budibase/server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"3.38.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-6x9p-4r67-5gjx/GHSA-6x9p-4r67-5gjx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"}]}