File Handling Vulnerability in NocoDB by NocoDB Inc.
CVE-2026-47385

5.3MEDIUM

Key Information:

Vendor

Nocodb

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-47385?

NocoDB, a platform that allows users to build databases in a spreadsheet-like manner, has a significant file handling vulnerability. An authenticated user with the base-create permission could manipulate SQLite sources to point to any arbitrary file on the host system. This includes the NocoDB internal database files, enabling potential read and overwrite actions through standard table APIs. This security issue arises from inadequate restrictions on file locations when handling caller-supplied filenames, allowing users to access sensitive files within the NocoDB environment. The issue has been addressed in version 2026.05.1.

Affected Version(s)

nocodb < 2026.05.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.