# sonatype-2026-005073

@budibase/server - Exposure of Sensitive Information to an Unauthorized Actor

Published Jul 25, 2026

[Advisory · GHSA-gh4h-34gr-87r7](https://github.com/advisories/GHSA-gh4h-34gr-87r7)

**CVSS Score** Medium 5.7

## Security Details

### Components Impacted

- **Source**: Sonatype Research

### CVE ID

- **CVE ID**: sonatype-2026-005073
- **CVE Description**: @budibase/server - Exposure of Sensitive Information to an Unauthorized Actor
- **Published**: Jul 25, 2026
- **CVSS Score & Severity**: 5.7 Medium
- **CVSS Vector**: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
- **EPSS Score**: 0%
- **Malware**: malware
- **KEV Status**: Not in KEV Catalog: No known exploits

### Affected Ecosystems

- **Source**: Sonatype

### References

- [GitHub · Advisory · GHSA-gh4h-34gr-87r7](https://github.com/advisories/GHSA-gh4h-34gr-87r7 "https://github.com/advisories/GHSA-gh4h-34gr-87r7")
