SQL Injection Vulnerability in NocoDB by NocoDB
CVE-2026-28399
6.2MEDIUM
What is CVE-2026-28399?
NocoDB, a platform that allows users to create databases as spreadsheets, is susceptible to an SQL injection vulnerability when an authenticated user with a Creator role utilizes the DATEADD formula's unit parameter. This flaw could allow the execution of arbitrary SQL commands, potentially compromising data integrity and security. The issue has been resolved in version 0.301.3. Users are strongly encouraged to update their installations to the latest version to mitigate these risks. For more details, visit the official advisory and release notes.
Affected Version(s)
nocodb < 0.301.3
