NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.37, NocoBase's workflow HTTP request plugin and custom request action plugin make server-side HTTP requests to user-provided URLs without any SSRF protection. An authenticated user can access internal network services, cloud metadata endpoints, and localhost. Version 2.0.37 contains a patch.
References
| Link | Resource |
|---|---|
| https://github.com/nocobase/nocobase/commit/2853368243ed07339c62c548b7d475f4eeaada59 | Patch |
| https://github.com/nocobase/nocobase/pull/9079 | Exploit Patch |
| https://github.com/nocobase/nocobase/releases/tag/v2.0.37 | Release Notes |
| https://github.com/nocobase/nocobase/security/advisories/GHSA-mvvv-v22x-xqwp | Exploit Vendor Advisory |
Configurations
History
13 May 2026, 20:53
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/nocobase/nocobase/commit/2853368243ed07339c62c548b7d475f4eeaada59 - Patch | |
| References | () https://github.com/nocobase/nocobase/pull/9079 - Exploit, Patch | |
| References | () https://github.com/nocobase/nocobase/releases/tag/v2.0.37 - Release Notes | |
| References | () https://github.com/nocobase/nocobase/security/advisories/GHSA-mvvv-v22x-xqwp - Exploit, Vendor Advisory | |
| CPE | cpe:2.3:a:nocobase:nocobase:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| First Time |
Nocobase
Nocobase nocobase |
18 Apr 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-18 00:16
Updated : 2026-05-13 20:53
NVD link : CVE-2026-40346
Mitre link : CVE-2026-40346
CVE.ORG link : CVE-2026-40346
JSON object : View
Products Affected
nocobase
- nocobase
CWE
CWE-918
Server-Side Request Forgery (SSRF)
