CVE-2026-55410 is a vulnerability in NocoBase, an AI-powered no-code/low-code platform, which allows a backup-management user to execute commands as the NocoBase server process by restoring a crafted backup. This issue is fixed in version 2.1.19. The vulnerability is caused by the @nocobase/plugin-backups component interpolating the database.schema value from _metadata.json into shell command strings exec [truncated]
CVE-2026-52888 is a vulnerability in NocoBase 2.0.59 and earlier. The @nocobase/plugin-collection-sql used the checkSQL() function with an incomplete keyword blacklist, allowing an admin-role user to read password hashes and database metadata through the SQL Collection feature. This vulnerability is fixed in 2.1.0-alpha.46. The vulnerability has a CVSS score of 6.8 and a severity of MEDIUM. Users of NocoB [truncated]
CVE-2026-52887 is a critical vulnerability in NocoBase, an AI-powered no-code/low-code platform used for building business applications and enterprise solutions. The vulnerability affects versions prior to 2.0.61 and involves the @nocobase/plugin-notification-in-app-message component. Specifically, the GET /api/myInAppChannels:list endpoint is exposed to stacked PostgreSQL statement injection. This occurs [truncated]
CVE-2026-58468 is a server-side request forgery vulnerability in NocoBase through 2.1.20. Authenticated administrators can issue arbitrary outbound HTTP requests by supplying malicious URLs to workflow request nodes, custom request action buttons, or the AI plugin. This allows attackers to target loopback addresses, RFC-1918 private ranges, and cloud instance metadata endpoints to perform internal network [truncated]