(0Day) Airbyte OneDrive Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability
Vulnerability Details
This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability.
The specific flaw exists within the _get_shared_drive_object method. The issue results from the lack of proper validation of a URI prior to accessing resources. An attacker can leverage this vulnerability to disclose information in the context of the service account.
Additional Details
10/29/25 – ZDI reported the vulnerabilities to the vendor
02/02/26 – ZDI followed up asking the vendor to confirm receipt of the reports
03/30/26 – ZDI notified the vendor of the intention to publish the case as a 0-day advisory
-- Mitigation: Given the nature of the vulnerability, the only salient mitigation strategy is to restrict interaction with the product
Disclosure Timeline
- 2025-10-29 - Vulnerability reported to vendor
- 2026-09-16 - Coordinated public release of advisory
- 2026-09-16 - Advisory Updated
Credit
Peter Girnus (@gothburz) and Brandon Niemczyk of Trend Zero Day Initiative