PT-2026-50476 · Nocodb · Nocodb
Published
2026-06-17
·
Updated
2026-06-23
·
CVE-2026-53930
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
NocoDB versions prior to 2026.05.1
Description
The 'base-migration' endpoint accepts a caller-supplied URL that the migration worker dereferences without enforcing the protocol or destination. This allows for scheme abuse, such as using
file: or ftp:, and the probing of internal HTTP destinations. Specifically, the body.migrationUrl variable in the 'migrate' endpoint lacked protocol validation, which could coerce the migration worker into reading local files or communicating with non-HTTP services. Access to this endpoint is restricted to the workspace owner role via Access Control List (ACL).Recommendations
Update to version 2026.05.1.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nocodb