NocoDB是nocodb公司开源的一个 Airtable 替代品。将任何 MySql、PostgreSql、Sql Server、Sqlite 和 MariaDb 转换为智能电子表格。 NocoDB 2026.05.1之前版本存在服务端请求伪造漏洞,该漏洞源于spreadsheet-fetch端点(axiosRequestMake)接受路径中包含允许扩展名的URL,并应用了手工编写的正则表达式黑名单,该黑名单遗漏了127.0.0.0/8和169.254.0.0/16,导致可以通过特制URL访问云元数据端
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-46551 | 6.5 MEDIUM | NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk E |
| CVE-2026-46547 | 6.1 MEDIUM | NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL |
| CVE-2026-47375 | 6.0 MEDIUM | NocoDB: Postgres SQL Injection in Formula `ARRAYSORT` |
| CVE-2026-46552 | 5.8 MEDIUM | NocoDB: Shared-base link access can invite arbitrary users as persistent base members |
| CVE-2026-46550 | 5.4 MEDIUM | NocoDB: Refresh Token Cookie Set Without `Secure` and `SameSite` Flags |
| CVE-2026-46548 | 4.3 MEDIUM | NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost |
| CVE-2026-46549 | 2.0 LOW | NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation |
| CVE-2026-47386 | NocoDB: OAuth Authorization Code Race Condition | |
| CVE-2026-46553 | NocoDB: Attachment Size Limit Bypass via Upload-by-URL | |
| CVE-2026-46554 | NocoDB: Stale Auth Cache After API Token Deletion | |
| CVE-2026-47385 | NocoDB: Path Traversal via SQLite Source Filename | |
| CVE-2026-47382 | NocoDB: Server-Side Request Forgery via Database Connection Host | |
| CVE-2026-47376 | NocoDB: Reflected Cross-Site Scripting via Password Reset Token | |
| CVE-2026-47384 | NocoDB: SQL Injection via Column Title in Bulk GroupBy | |
| CVE-2026-53929 | NocoDB: Stored Cross-Site Scripting via Secure Attachment | |
| CVE-2026-47377 | NocoDB: Open Redirect via Hash Fragment in hashRedirect Plugin | |
| CVE-2026-47381 | NocoDB: Cross-Workspace Integration Use in Connection Test | |
| CVE-2026-47378 | NocoDB: Hidden Column Exposure in Public Shared View Endpoints | |
| CVE-2026-47379 | NocoDB: Plaintext Password Comparison in Shared Views | |
| CVE-2026-47388 | NocoDB: Missing Ownership Check in MCP Attachment Read |
Showing top 20 of 29 CVEs. View all on vendor page → →
No comments yet