CyberRota Analysis
AI-GeneratedBudibase versions prior to 3.40.0 are vulnerable to a cross-site request forgery (CSRF) flaw in the chat-link handoff endpoint, allowing attackers to associate an external chat identity with a victim's account. This exploitation can lead to unauthorized impersonation within agent operations and the inheritance of victim permissions, posing significant risks to user data and operational integrity. Organizations using affected versions should prioritize patching to mitigate potential impersonation and security breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a victim's account. Attackers can craft a phishing page that auto-submits a POST request with a leaked confirmation token to bind their chat identity to a victim user's account, enabling impersonation within agent operations and inheritance of victim permissions.