Cross-site scripting in NocoDB - CVE-2026-28359
Published: April 27, 2026
NocoDB
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in the browser of another user.
The vulnerability exists due to cross-site scripting in the Rich Text field rendering path when processing raw HTML submitted via the API. A remote user can send crafted HTML content to execute arbitrary script in the browser of another user.
The issue affects content rendered via v-html in TextArea.vue through NcMarkdownParser.parse(), and viewing the stored cell is required for exploitation.