@fede.bubble Can you kindly raise this internally? This was highlighted to us by an external pentest. Feels quite ridicilous, i’m able to add files to any bubble app, with unauthenticated access.