HTML Injection Vulnerability in NocoDB Software by NocoDB
CVE-2026-28359
5.3MEDIUM
What is CVE-2026-28359?
NocoDB, a software solution for building databases in a spreadsheet format, is susceptible to an HTML injection vulnerability. This issue occurs when an authenticated user with Editor privileges can bypass the TipTap editor and inject arbitrary HTML into Rich Text cells through direct API interactions. This can lead to unauthorized content alteration and potential exploitation. Users are advised to upgrade to version 0.301.3, where this vulnerability has been addressed to enhance security and protect data integrity.
Affected Version(s)
nocodb < 0.301.3
