Cross-site scripting in NocoDB - CVE-2026-46547
Published: May 23, 2026
NocoDB
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary JavaScript in the context of the application.
The vulnerability exists due to cross-site scripting in the Page Leaving Warning page when processing crafted ncRedirectUrl and ncBackUrl query parameters. A remote attacker can send a specially crafted link to a victim to execute arbitrary JavaScript in the context of the application.
User interaction is required to open the crafted link.