{"id":"CVE-2026-54356","aliases":["GHSA-6x9p-4r67-5gjx"],"url":"https://o3.security/vulnerability/CVE-2026-54356","summary":"Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`","details":"### Summary\nBudibase 3.39.7 allows a low-privilege authenticated published-app user with the built-in BASIC role to obtain arbitrary S3 pre-signed upload URLs backed by a workspace datasource's stored server-side credentials.\n\nThe affected endpoint is:\n\n`POST /api/attachments/:datasourceId/url`\n\nThe caller can control:\n```text\nbucket\nkey\n```\nand receives:\n```text\nsignedUrl\npublicUrl\n```\n\nThis lets a low-privilege published-app user mint S3 `PUT` URLs using server-side datasource credentials for attacker-chosen object destinations.\n\nSteps:\n\n1. Log in as an admin user.\n2. Create a new app/workspace.\n3. In the development app context, create an S3 datasource with valid credentials.\n4. Publish the app.\n5. Create a low-privilege user with the built-in BASIC role on the published production app ID.\n6. Log in as that BASIC user.\n7. Send:\n`POST /api/attachments/<datasourceId>/url`\n\nwith:\n```json\n{\"bucket\":\"foo\",\"key\":\"bar\"}\n```\nand the published app header:\n```text\nx-budibase-app-id: <published_app_id>\n```\nObserve a successful response containing:\n```text\nsignedUrl\npublicUrl\n```\n\n### Observed result\n\nThe following behavior:\n\ndev BASIC request: 403 User does not have permission\napp publish: SUCCESS\nprod BASIC request: 200 OK\nExample confirmed runtime values from the final successful run:\n```text\nprodAppId: app_e6b4cdc6cd6949969a83ff11eee88c5a\ndatasourceId: datasource_0cec491b26a742468257c62382aa3284\npublicUrl: https://foo.s3.eu-west-1.amazonaws.com/bar\n```\nThe returned signedUrl contained standard AWS signing markers, including:\n```text\nX-Amz-Credential=bb\nX-Amz-Signature\nX-Amz-Expires=900\n```\n### Impact\n\nA low-privilege published-app user who knows a valid datasource ID can mint S3 upload URLs backed by server-side datasource credentials and choose arbitrary destination bucket and key values.\n\n### Route definition\n`packages/server/src/api/routes/static.ts:45`\nAuthorization logic\n`packages/server/src/middleware/authorized.ts`\n`packages/server/src/middleware/resourceId.ts`\nController logic\n`packages/server/src/api/controllers/static/index.ts`\nDatasource lookup\n`packages/server/src/sdk/workspace/datasources/datasources.ts`","published":"2026-08-17T20:32:05.691Z","modified":"2026-09-10T03:30:32.487885274Z","cvss":{"score":7.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"@budibase/server","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/Budibase/budibase/releases/tag/3.41.3"},{"type":"ADVISORY","url":"https://github.com/Budibase/budibase/security/advisories/GHSA-6x9p-4r67-5gjx"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54356.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54356"},{"type":"PACKAGE","url":"https://github.com/Budibase/budibase"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:30:32.487885274Z"}}