PT-2026-22635 · Nocodb · Nocodb
Bugbunny-Research
·
Published
2026-03-02
·
Updated
2026-03-03
·
CVE-2026-28398
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
NocoDB versions prior to 0.301.3
Description
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, user-controlled content in comments and rich text cells was rendered via
v-html without sanitization, enabling stored cross-site scripting (XSS). The issue occurs because content provided by users is not properly processed before being displayed, potentially allowing malicious code to be executed within the application.Recommendations
Update to version 0.301.3 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nocodb