Application Layer Vulnerability in NocoDB by NocoDB Team
CVE-2026-53927

5.1MEDIUM

Key Information:

Vendor

Nocodb

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-53927?

NocoDB, a platform for building databases as spreadsheets, has a vulnerability that allows unauthorized access to its cloud-metadata endpoint. This occurs due to insufficient validation on URLs sent to the spreadsheet-fetch endpoint (axiosRequestMake). Prior to version 2026.05.1, the application did not properly filter paths against a comprehensive blocklist, inadvertently exposing sensitive metadata. This exploit could be triggered by carefully crafted URLs that bypass normal validations, potentially allowing attackers to extract information from secured endpoints.

Affected Version(s)

nocodb < 2026.05.1

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.