Description
GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge of a publicly shared report or experiment identifier can read internal data warehouse query text, schema, table names, filter values and datasource identifiers.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive data exposure
Action: Immediate Patch
AI Analysis

Impact

GrowthBook versions up to 5.0.1 expose fact table definitions in the payload of public report and experiment endpoints. The unredacted data includes raw SQL queries to the data warehouse, the schema and table names knows or can guess a publicly shared report, leaking confidential business information and potentially sensitive data.

Affected Systems

The affected product is GrowthBook, version 5.0.1 and any earlier releases. The vulnerability is triggered by the unauthenticated public report and experiment endpoints that are available to anyone who possesses a report or experiment identifier. The issue is present in the back‑end code that serves these endpoints and is not confined to specific deployment environments.

Risk and Exploitability

The CVSS score of 6.9 falls into the medium severity range, reflectingSS score is < 1%, indicating a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting it is not currently a widely exploited risk. The attack vector is likely through an unauthenticated HTTP request to a public report or experiment URL supplied with a known identifier; the attacker must or enumeration. Successful exploitation leads to disclosure of sensitive internal data but does not provide code‑execution or persistent presence.

Generated by OpenCVE AI on September 17, 2026 at 19:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GrowthBook to version 5.0.2
  • Remove or rotate any public report or experiment identifiers that are already exposed or could be guessed.
  • Implement authentication or restrict access to public report and experiment endpoints to prevent unauthenticated disclosure.

Generated by OpenCVE AI on September 17, 2026 at 19:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge of a publicly shared report or experiment identifier can read internal data warehouse query text, schema, table names, filter values and datasource identifiers.
Title GrowthBook through 5.0.1 Information Disclosure via Public Endpoints
First Time appeared Growthbook
Growthbook growthbook
Weaknesses CWE-201
CPEs cpe:2.3:a:growthbook:growthbook:*:*:*:*:*:*:*:*
Vendors & Products Growthbook
Growthbook growthbook
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Growthbook Growthbook
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:15.225Z

Reserved: 2026-09-14T21:55:42.972Z

Link: CVE-2026-91198

cve-icon Vulnrichment

Updated: 2026-09-15T19:11:28.151Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T23:19:00.323

Modified: 2026-09-16T19:47:01.197

Link: CVE-2026-91198

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:30:18Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data