GHSA-pvcr-8mvp-w8qr: Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
Summary
Budibase has a vulnerability in its chat-link handoff feature where an attacker can trick a victim user into linking the victim's account to the attacker's external chat identity (like Slack or Discord). The vulnerability exists because the confirmation endpoint is publicly accessible without proper security checks, the confirmation token is visible in plaintext on the confirmation page, and there is no CSRF token (a security check that prevents unauthorized requests) protecting the confirmation step. Once linked, the attacker can impersonate the victim user when sending messages through the chat, gaining access to the victim's permissions and data.
Classification
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-pvcr-8mvp-w8qr
First tracked: July 24, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 85%