Nocobase是NocoBase公司开源的一个低代码平台。 NocoBase 2.1.0-alpha.46之前版本存在安全漏洞,该漏洞源于SQL Collection功能的checkSQL()函数使用了不完整的关键词黑名单,未限制PostgreSQL系统目录表,允许admin角色用户读取密码哈希值和数据库元数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-52887 | 10.0 CRITICAL | NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE |
| CVE-2026-55410 | 6.7 MEDIUM | NocoBase backup restore schema name allows command injection |
No comments yet