Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 14 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge of a publicly shared report or experiment identifier can read internal data warehouse query text, schema, table names, filter values and datasource identifiers. | |
| Title | GrowthBook through 5.0.1 Information Disclosure via Public Endpoints | |
| First Time appeared |
Growthbook
Growthbook growthbook |
|
| Weaknesses | CWE-201 | |
| CPEs | cpe:2.3:a:growthbook:growthbook:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Growthbook
Growthbook growthbook |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T19:11:32.089Z
Reserved: 2026-09-14T21:55:42.972Z
Link: CVE-2026-91198
Updated: 2026-09-15T19:11:28.151Z
Status : Received
Published: 2026-09-14T23:19:00.323
Modified: 2026-09-15T19:17:47.280
Link: CVE-2026-91198
No data.
OpenCVE Enrichment
Updated: 2026-09-15T10:00:16Z
-
CWE-201
Insertion of Sensitive Information Into Sent Data