Cross-site scripting in NocoDB - CVE-2026-28357
Published: April 27, 2026
NocoDB
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in users' browsers.
The vulnerability exists due to cross-site scripting in the Formula virtual cell when rendering formula results containing URI::() patterns via v-html without sanitization. A remote user can create a crafted formula field value to execute arbitrary script in users' browsers.
Exploitation requires the Creator role and occurs when another user views the affected table.