PT-2026-22636 · Nocodb · Nocodb

Q1Uf3Ng

·

Published

2026-03-02

·

Updated

2026-03-25

·

CVE-2026-28399

CVSS v3.1

8.8

High

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NocoDB versions prior to 0.301.3
Description NocoDB is software for building databases as spreadsheets. An authenticated user with Creator role can inject arbitrary SQL via the DATEADD formula's unit parameter. The issue affects versions prior to 0.301.3.
Recommendations Update to version 0.301.3 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-28399
GHSA-45RP-9P97-H852

Affected Products

Nocodb