Nocobase是NocoBase公司开源的一个低代码平台。 NocoBase 2.1.19之前版本存在命令注入漏洞,该漏洞源于@nocobase/plugin-backups插件在恢复PostgreSQL备份时,将_metadata.json中的database.schema值插入到通过Node.js child_process.exec()执行的shell命令字符串中,可能导致备份管理用户恢复特制备份时以NocoBase服务器进程执行命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-52887 | 10.0 CRITICAL | NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE |
| CVE-2026-52888 | 6.8 MEDIUM | NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass |
No comments yet