PT-2026-22634 · Nocodb · Nocodb

P-

·

Published

2026-03-02

·

Updated

2026-03-03

·

CVE-2026-28397

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions NocoDB versions prior to 0.301.3
Description NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, comments rendered via v-html without sanitization enable stored Cross-Site Scripting (XSS). This allows for the injection of malicious scripts into comments, which are then executed when other users view those comments. The v-html directive bypasses standard HTML encoding, potentially allowing attackers to execute arbitrary JavaScript code within the context of the application.
Recommendations Update to version 0.301.3 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-28397
GHSA-RCPH-X7MJ-54MM

Affected Products

Nocodb