CRITICAL
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
Published Jul 15, 2026
10.0
CRITICALCVSS 3.1
EPSS 0.89%
Description
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal() template string without escaping or parameter binding, allowing a signed-up authenticated user to run stacked PostgreSQL statements and potentially execute commands with COPY ... TO PROGRAM. This vulnerability is fixed in 2.0.61.
Affected products
-
- Version < 2.0.61StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
@nocobase/plugin-notification-in-app-message
npm
Introduced 0 Fixed 2.0.61
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @nocobase/plugin-notification-in-app-message | 0 | 2.0.61 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44802 Advisory
- https://github.com/advisories/GHSA-p849-8hwh-84j9 Advisory
- https://github.com/nocobase/nocobase/commit/68d64e3fcfb8be2ae4f3bfc9e1ee3f85b87c89ce x_refsource_MISC
- https://github.com/nocobase/nocobase/pull/9630
- https://github.com/nocobase/nocobase/releases/tag/v2.0.61 x_refsource_MISC
- https://github.com/nocobase/nocobase/security/advisories/GHSA-p849-8hwh-84j9 exploitx_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-52887
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 15, 2026
Updated Jul 20, 2026
Reserved Jun 8, 2026
Link CVE-2026-52887
CISA Vulnrichment
Updated Jul 20, 2026
ENISA EUVD
EUVD-2026-44802 GHSA-P849-8HWH-84J9 Assigner GitHub_M
Published Jul 15, 2026
Updated Jul 20, 2026
Exploited since n/a
Link EUVD-2026-44802