CVE-2026-91198

Summary

GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge of a publicly shared report or experiment identifier can read internal data warehouse query text, schema, table names, filter values and datasource identifiers.

Affected Software

VendorProductVersion RangeStatus
growthbookgrowthbook0 <= 5.0.1affected

Weaknesses

  • CWE-201: Insertion of Sensitive Information Into Sent Data

References