CVE-2026-53929

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, with NC_SECURE_ATTACHMENTS=true, an authenticated uploader could deliver .html or .svg attachments that the browser rendered inline from the NocoDB origin instead of forcing a download. The signed attachment handler stored response-header overrides under PascalCase keys (ResponseContentDisposition, ResponseContentType) while the controller that served the file read them under lowercase-hyphen names (response-content-disposition). The mismatch dropped the Content-Disposition: attachment header, leaving Express to auto-render .html, .svg, and similar inline. This vulnerability is fixed in 2026.05.1.
CVSS

No CVSS.

Configurations

No configuration.

History

23 Jun 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-23 21:17

Updated : 2026-06-25 20:17


NVD link : CVE-2026-53929

Mitre link : CVE-2026-53929

CVE.ORG link : CVE-2026-53929


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')