GHSA-gv2h-crgm-gfwcMediumCVSS 5.3

GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in...

Published
September 15, 2026
Last Modified
September 15, 2026

🔗 CVE IDs covered (1)

📋 Description

GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge of a publicly shared report or experiment identifier can read internal data warehouse query text, schema, table names, filter values and datasource identifiers.

🔗 References (7)