SQL Injection Vulnerability in NocoDB Software by NocoDB
CVE-2026-47375
6MEDIUM
What is CVE-2026-47375?
NocoDB is a platform designed for building databases in a spreadsheet format. An identified vulnerability allows authenticated users with columnAdd permissions on a Postgres-backed database to inject arbitrary SQL into the formula engine using an unrestricted direction argument in the ARRAYSORT function. This unsafe input is processed with knex.raw and executes in the context of a column creation and during each read of the formula column, potentially compromising data integrity. This issue has been addressed in version 2026.04.1.
Affected Version(s)
nocodb < 2026.04.1
