Impact
GrowthBook versions up to 5.0.1 expose fact table definitions in the payload of public report and experiment endpoints. The unredacted data includes raw SQL queries to the data warehouse, the schema and table names knows or can guess a publicly shared report, leaking confidential business information and potentially sensitive data.
Affected Systems
The affected product is GrowthBook, version 5.0.1 and any earlier releases. The vulnerability is triggered by the unauthenticated public report and experiment endpoints that are available to anyone who possesses a report or experiment identifier. The issue is present in the back‑end code that serves these endpoints and is not confined to specific deployment environments.
Risk and Exploitability
The CVSS score of 6.9 falls into the medium severity range, reflectingSS score is < 1%, indicating a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting it is not currently a widely exploited risk. The attack vector is likely through an unauthenticated HTTP request to a public report or experiment URL supplied with a known identifier; the attacker must or enumeration. Successful exploitation leads to disclosure of sensitive internal data but does not provide code‑execution or persistent presence.
OpenCVE Enrichment