Back

CRITICAL

NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

Published Jul 15, 2026

Description

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal() template string without escaping or parameter binding, allowing a signed-up authenticated user to run stacked PostgreSQL statements and potentially execute commands with COPY ... TO PROGRAM. This vulnerability is fixed in 2.0.61.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 15, 2026
Updated Jul 20, 2026
Reserved Jun 8, 2026
CISA Vulnrichment
Updated Jul 20, 2026
NVD
Status Deferred
Modified Jul 20, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Jul 15, 2026
Updated Jul 20, 2026
Exploited since n/a
EUVD-2026-44802 GHSA-P849-8HWH-84J9