Open Redirect Vulnerability in NocoDB Software
CVE-2026-24768
What is CVE-2026-24768?
NocoDB, a software tool designed for building databases as spreadsheets, has an open redirect vulnerability in its login flow affecting versions before 0.301.0. This issue arises from the lack of validation for the continueAfterSignIn parameter, which allows attackers to intercept user sessions. By exploiting this flaw, malicious actors can redirect authenticated users to external websites of their choice post-login. While this vulnerability does not directly compromise user credentials or allow unauthorized access, it significantly heightens the risk of phishing attacks, as attackers can manipulate user trust in the legitimate NocoDB interface. NocoDB has addressed this issue in version 0.301.0, reinforcing authentication integrity and protecting users from potential social engineering attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
nocodb < 0.301.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
