Hi all,

Jumping in here for a bit of moderation. Thank you to folks who reported this, both here and via email. We’re looking into this situation. As users have pointed out, this is not a security gap on the Bubble platform side, but in how certain plugins are being built. But, there are some things we’re considering on our end to reduce the risk of this hurting users going forward.

For the security of users of those plugins, I have edited posts in this thread to remove specific plugin references. We will be following up with those plugin authors directly. If you know of more plugins that have this issue, please DM them to me or email them to our Success team.

Note that here and in the future with any kind of security issue, we ask that you follow responsible disclosure principles, namely to reach out to us (if it’s a Bubble platform concern) or the plugin creator and cc’ing us (if it’s a plugin) privately, instead of posting on the forum. This gives the plugin creator / us a chance to work on a fix without publicizing the issue, which can then be exploited by others while the fix is in the works.

Given that, I am also closing this thread for now while we deal with this. Again, if you know of other plugins that have this issue, please let us know privately, and we’ll approach that plugin creator.

Thanks,
Allen

3 Likes