File Access Vulnerability in NocoDB by NocoDB
CVE-2026-47388

2.3LOW

Key Information:

Vendor

Nocodb

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-47388?

A vulnerability in NocoDB, prior to version 2026.05.1, allows a low-privilege user holding an MCP token to read any file in shared storage, including attachments from different bases and workspaces. This occurs due to insufficient verification of file ownership in the MCP readAttachment tool, potentially exposing sensitive data to unauthorized users.

Affected Version(s)

nocodb < 2026.05.1

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.