SQL Injection Vulnerability in NocoDB by NocoDB
CVE-2026-28399

6.2MEDIUM

Key Information:

Vendor

Nocodb

Status
Vendor
CVE Published:
2 March 2026

What is CVE-2026-28399?

NocoDB, a platform that allows users to create databases as spreadsheets, is susceptible to an SQL injection vulnerability when an authenticated user with a Creator role utilizes the DATEADD formula's unit parameter. This flaw could allow the execution of arbitrary SQL commands, potentially compromising data integrity and security. The issue has been resolved in version 0.301.3. Users are strongly encouraged to update their installations to the latest version to mitigate these risks. For more details, visit the official advisory and release notes.

Affected Version(s)

nocodb < 0.301.3

References

CVSS V4

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.