HTTP Proxy Vulnerability in NocoDB Software
CVE-2026-53931

6.9MEDIUM

Key Information:

Vendor

Nocodb

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-53931?

NocoDB, a platform for building databases in a spreadsheet-like interface, has a security issue in its spreadsheet-import endpoint. This vulnerability allows unauthenticated users to exploit the endpoint axiosRequestMake as a generic HTTP proxy. Prior to the release of version 2026.05.1, the implementation of URL verification was inadequate, as it relied on a regex check against the entire URL string. As a result, any URLs with a query string ending in .csv could bypass the security measures, potentially leading to unauthorized data access and retrieval from different endpoints. This flaw has been addressed in version 2026.05.1.

Affected Version(s)

nocodb < 2026.05.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.