Information Disclosure Vulnerability in GrowthBook by GrowthBook
CVE-2026-91198

6.9MEDIUM

Key Information:

Vendor

Growthbook

Vendor
CVE Published:
14 September 2026

What is CVE-2026-91198?

The GrowthBook platform through version 5.0.1 has a serious information disclosure vulnerability wherein it inadvertently exposes unredacted fact table definitions. This occurs in payloads delivered via unauthenticated public reporting and experiment endpoints. Cyber attackers who can access a shared report or experiment identifier may exploit this flaw to view internal data warehouse query texts, schema structures, table names, filter values, and data source identifiers, potentially leading to unauthorized access to sensitive database information.

Affected Version(s)

growthbook 0 <= 5.0.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.