HTML Injection Vulnerability in NocoDB Software by NocoDB
CVE-2026-28359

5.3MEDIUM

Key Information:

Vendor

Nocodb

Status
Vendor
CVE Published:
2 March 2026

What is CVE-2026-28359?

NocoDB, a software solution for building databases in a spreadsheet format, is susceptible to an HTML injection vulnerability. This issue occurs when an authenticated user with Editor privileges can bypass the TipTap editor and inject arbitrary HTML into Rich Text cells through direct API interactions. This can lead to unauthorized content alteration and potential exploitation. Users are advised to upgrade to version 0.301.3, where this vulnerability has been addressed to enhance security and protect data integrity.

Affected Version(s)

nocodb < 0.301.3

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.