CVE-2026-47384

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated user with column-create permission can inject SQL into the bulk groupBy endpoint by setting a column's title to a SQL fragment. The bulk groupBy path in group-by.ts builds three database-specific knex.raw() aggregations that interpolate the request's column_name directly into the SQL string. Column lookup in data-table.service.ts matches on both the sanitized column_name field and the free-text title, so a title containing a SQL fragment bypasses the public endpoint's existing column allowlist and reaches the query builder unescaped. This vulnerability is fixed in 2026.05.1.
CVSS

No CVSS.

Configurations

No configuration.

History

23 Jun 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-23 21:17

Updated : 2026-06-25 14:21


NVD link : CVE-2026-47384

Mitre link : CVE-2026-47384

CVE.ORG link : CVE-2026-47384


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')