PatchSiren cyber security CVE debrief
CVE-2026-53931 nocodb CVE debrief
CVE-2026-53931 is a vulnerability in NocoDB, a software for building databases as spreadsheets. The spreadsheet-import endpoint, axiosRequestMake, could be used as a generic HTTP proxy before version 2026.05.1. This endpoint was reachable unauthenticated and had a URL-extension allowlist that was a regex tested against the full URL string. This allowed URLs whose query string ended in .csv to bypass the gate even if the underlying request was for another file. The vulnerability is fixed in version 2026.05.1. Users should update to this version to prevent potential unauthorized access. Additionally, defenders should monitor for suspicious activity and implement compensating controls to mitigate potential risks.
- Vendor
- nocodb
- Product
- Unknown
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-23
- Original CVE updated
- 2026-06-25
- Advisory published
- 2026-06-23
- Advisory updated
- 2026-06-25
Who should care
Users of NocoDB, especially those who have not updated to version 2026.05.1, should be aware of this vulnerability. IT teams and security professionals responsible for maintaining and securing database systems should prioritize updating NocoDB to the latest version. Monitoring for suspicious activity and implementing compensating controls can help mitigate potential risks.
Technical summary
The vulnerability in NocoDB's spreadsheet-import endpoint allows an attacker to use it as a generic HTTP proxy. This is possible because the endpoint is reachable unauthenticated and the URL-extension allowlist is a regex tested against the full URL string. An attacker can bypass the allowlist by appending .csv to the query string of a URL, even if the underlying request is for another file. The fix in version 2026.05.1 addresses this issue by properly securing the endpoint. Technical teams should ensure that NocoDB is updated to this version to prevent exploitation.
Defensive priority
High priority should be given to updating NocoDB to version 2026.05.1. In the meantime, defenders should monitor for suspicious activity and implement compensating controls to mitigate potential risks.
Recommended defensive actions
- Update NocoDB to version 2026.05.1 or later.
- Monitor for suspicious activity on the network.
- Implement compensating controls to mitigate potential risks.
- Review and update security policies and procedures.
- Perform vulnerability scanning and penetration testing.
Evidence notes
The CVE record and NVD detail provide information on the vulnerability and its fix. The source item URL provides additional context on the vulnerability. The reference to the GitHub security advisory provides further details on the vulnerability and its fix.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-53931 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-53931
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-53931 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-53931
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/nocodb/nocodb/security/advisories/GHSA-hmcr-rmjq-47qr
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.