Cross-site scripting in NocoDB - CVE-2026-24769

 

Cross-site scripting in NocoDB - CVE-2026-24769

Published: April 27, 2026


Vulnerability identifier: #VU127980
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-24769
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in the browsers of other users.

The vulnerability exists due to cross-site scripting in the attachment handling mechanism when rendering uploaded SVG attachments inline. A remote user can upload a malicious SVG file containing embedded JavaScript to execute arbitrary script in the browsers of other users.

Exploitation requires permission to upload attachments, and user interaction is required when another user views the attachment.


Affected software

NocoDB

How to mitigate CVE-2026-24769

Install security update from vendor's website.

NocoDB - update to 0.301.0

External References

Related Security Bulletins