# sonatype-2026-005080

@budibase/server - Exposure of Sensitive Information to an Unauthorized Actor

Published Jul 25, 2026

[Advisory · GHSA-hr66-5mqr-8mpx](https://github.com/advisories/GHSA-hr66-5mqr-8mpx)

## Security Details

### Components Impacted

Sonatype Research

### sonatype-2026-005080 Security Details

**CVE ID:** sonatype-2026-005080  
**CWE:** N/A  
**CVE Description:** @budibase/server - Exposure of Sensitive Information to an Unauthorized Actor  
**Published:** Jul 25, 2026

### CVSS Score & Severity

**Score:** 7.5  
**Severity:** High

**CVSS Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N  
**EPSS Score:** 0%

### Malware Status

No known exploits

### Affected Ecosystems

Sonatype

### References

[GitHub · Advisory · GHSA-hr66-5mqr-8mpx](https://github.com/advisories/GHSA-hr66-5mqr-8mpx)
