Open Redirect Vulnerability in NocoDB Software
CVE-2026-24768

5.7MEDIUM

Key Information:

Vendor

Nocodb

Status
Vendor
CVE Published:
28 January 2026

What is CVE-2026-24768?

NocoDB, a software tool designed for building databases as spreadsheets, has an open redirect vulnerability in its login flow affecting versions before 0.301.0. This issue arises from the lack of validation for the continueAfterSignIn parameter, which allows attackers to intercept user sessions. By exploiting this flaw, malicious actors can redirect authenticated users to external websites of their choice post-login. While this vulnerability does not directly compromise user credentials or allow unauthorized access, it significantly heightens the risk of phishing attacks, as attackers can manipulate user trust in the legitimate NocoDB interface. NocoDB has addressed this issue in version 0.301.0, reinforcing authentication integrity and protecting users from potential social engineering attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

nocodb < 0.301.0

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.