SQL Injection Vulnerability in NocoDB Software by NocoDB
CVE-2026-47375

6MEDIUM

Key Information:

Vendor

Nocodb

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-47375?

NocoDB is a platform designed for building databases in a spreadsheet format. An identified vulnerability allows authenticated users with columnAdd permissions on a Postgres-backed database to inject arbitrary SQL into the formula engine using an unrestricted direction argument in the ARRAYSORT function. This unsafe input is processed with knex.raw and executes in the context of a column creation and during each read of the formula column, potentially compromising data integrity. This issue has been addressed in version 2026.04.1.

Affected Version(s)

nocodb < 2026.04.1

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.