---
id: CVE-2026-91198
title: >-
  GrowthBook through 5.0.1 returns unredacted fact table definitions including
  raw warehouse SQL in payloads served by unauthenticated public report and
  experiment endpoints
summary: >-
  GrowthBook through 5.0.1 returns unredacted fact table definitions including
  raw warehouse SQL in payloads served by unauthenticated public report and
  experiment endpoints. Attackers with knowledge of a publicly shared report or
  experime…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-201
vendor: growthbook
product: growthbook
affected:
  - growthbook <= 5.0.1
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:47:01.197'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91198'
references:
  - url: 'https://github.com/growthbook/growthbook'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/growthbook/growthbook/blob/57d07471b137eb43d9bfb1613d0a1203d21fef88/packages/back-end/src/app.ts#L391-L409
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/growthbook/growthbook/blob/57d07471b137eb43d9bfb1613d0a1203d21fef88/packages/back-end/src/services/reports.ts#L880-L890
    label: disclosure@vulncheck.com
  - url: 'https://github.com/growthbook/growthbook/issues/6541'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/growthbook-through-5.0.1-information-disclosure-via-public-endpoints
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00419
epssPercentile: 0.33498
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-15T19:11:23.764822Z'
ingestedAt: '2026-09-14T23:17:06.519Z'
---

## Overview

GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge of a publicly shared report or experiment identifier can read internal data warehouse query text, schema, table names, filter values and datasource identifiers.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
