HTTP Proxy Vulnerability in NocoDB Software
CVE-2026-53931
6.9MEDIUM
What is CVE-2026-53931?
NocoDB, a platform for building databases in a spreadsheet-like interface, has a security issue in its spreadsheet-import endpoint. This vulnerability allows unauthenticated users to exploit the endpoint axiosRequestMake as a generic HTTP proxy. Prior to the release of version 2026.05.1, the implementation of URL verification was inadequate, as it relied on a regex check against the entire URL string. As a result, any URLs with a query string ending in .csv could bypass the security measures, potentially leading to unauthorized data access and retrieval from different endpoints. This flaw has been addressed in version 2026.05.1.
Affected Version(s)
nocodb < 2026.05.1
