File Handling Vulnerability in NocoDB by NocoDB Inc.
CVE-2026-47385
5.3MEDIUM
What is CVE-2026-47385?
NocoDB, a platform that allows users to build databases in a spreadsheet-like manner, has a significant file handling vulnerability. An authenticated user with the base-create permission could manipulate SQLite sources to point to any arbitrary file on the host system. This includes the NocoDB internal database files, enabling potential read and overwrite actions through standard table APIs. This security issue arises from inadequate restrictions on file locations when handling caller-supplied filenames, allowing users to access sensitive files within the NocoDB environment. The issue has been addressed in version 2026.05.1.
Affected Version(s)
nocodb < 2026.05.1
