PatchSiren cyber security CVE debrief
CVE-2026-47385 nocodb CVE debrief
CVE-2026-47385 is a vulnerability in NocoDB, software for building databases as spreadsheets. An authenticated user with base-create permission can attach a SQLite source pointing at an arbitrary file on the NocoDB host, including NocoDB's own internal databases. The vulnerability is fixed in version 2026.05.1. Users should update to the latest version to prevent exploitation. The CVSS score for this vulnerability is 5.3, indicating a medium severity.
- Vendor
- nocodb
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-23
- Original CVE updated
- 2026-06-25
- Advisory published
- 2026-06-23
- Advisory updated
- 2026-06-25
Who should care
Users of NocoDB, especially those with base-create permissions, should be aware of this vulnerability and take steps to protect themselves. This includes updating to version 2026.05.1 or later and being cautious when attaching new sources. Security teams should also be aware of this vulnerability and monitor for potential exploitation.
Technical summary
The vulnerability in NocoDB allows an authenticated user with base-create permission to attach a SQLite source pointing at an arbitrary file on the NocoDB host. This is possible because the SQLite client and base/integration create services accept a caller-supplied filename and pass it to fs.exists and fs.open('w') without restricting the location. A user could point a source at noco.db, at a tenant database under nc_minimal_dbs/, or at any writable path the NocoDB process can reach, and then read or overwrite its contents through the regular table APIs.
Defensive priority
This vulnerability has a medium CVSS score of 5.3, indicating that it should be prioritized for remediation. Users should update to version 2026.05.1 or later as soon as possible to prevent exploitation.
Recommended defensive actions
- Update to version 2026.05.1 or later
- Be cautious when attaching new sources
- Monitor for potential exploitation
- Restrict permissions for base-create users
- Implement additional security measures to prevent arbitrary file access
Evidence notes
The evidence for this vulnerability comes from the NVD and CVE.org. The vulnerability is fixed in version 2026.05.1. The CVSS score for this vulnerability is 5.3, indicating a medium severity. There is limited information available about the vulnerability, so users should be cautious when attaching new sources.
Official resources
-
CVE-2026-47385 CVE record
CVE.org
-
CVE-2026-47385 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
This article is AI-assisted and based on the supplied source corpus.