Stored XSS Vulnerability in NocoDB Affects Database Functionality
CVE-2026-28357
5.3MEDIUM
What is CVE-2026-28357?
NocoDB, a platform designed for creating databases as spreadsheets, was found to have a stored XSS vulnerability prior to version 0.301.3. This vulnerability resides in the Formula virtual cell, where formula results consisting of unsafe URI::() patterns are rendered through v-html without appropriate sanitization measures. As a result, attackers can inject malicious HTML, leading to unauthorized script execution in user browsers. This issue has been resolved with the release of version 0.301.3, which includes necessary security enhancements.
Affected Version(s)
nocodb < 0.301.3
