Stored XSS Vulnerability in NocoDB Software for Spreadsheet Database Management
CVE-2026-28397
5.3MEDIUM
What is CVE-2026-28397?
NocoDB is a versatile software solution that transforms your databases into spreadsheet-like interfaces. However, prior to version 0.301.3, it had a vulnerability that allowed comments to be rendered via v-html without proper sanitization. This flaw could potentially enable attackers to exploit stored XSS attacks, compromising the security of applications utilizing NocoDB. The vulnerability has been addressed in version 0.301.3, enhancing the overall security of the platform.
Affected Version(s)
nocodb < 0.301.3
