# sonatype-2026-005079

@budibase/server - Exposure of Sensitive Information to an Unauthorized Actor

Published Jul 25, 2026

[Advisory · GHSA-fcrw-f7gg-6g9f](https://github.com/advisories/GHSA-fcrw-f7gg-6g9f)

**CVSS Score**: Medium 4.9

## Security Details

### Components Impacted

- Sonatype Research

### sonatype-2026-005079 Security Details

**CVE ID**: sonatype-2026-005079  
**CWE**: N/A  
**CVE Description**: @budibase/server - Exposure of Sensitive Information to an Unauthorized Actor  
**Published**: Jul 25, 2026  
**CVSS Score & Severity**: 4.9 Medium  
**CVSS Vector**: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N  
**EPSS Score**: 0%

### Malware
- malware

### KEV Status
- Not in KEV Catalog: No known exploits

### Affected Ecosystems
- affected

**Source**: Sonatype

**References**:  
[GitHub · Advisory · GHSA-fcrw-f7gg-6g9f](https://github.com/advisories/GHSA-fcrw-f7gg-6g9f "https://github.com/advisories/GHSA-fcrw-f7gg-6g9f")
