PT-2026-50477 · Nocodb · Nocodb

·

CVE-2026-53931

·

Published

2026-06-17

·

Updated

2026-06-25

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions NocoDB versions prior to 2026.05.1
Description The 'spreadsheet-import' endpoint axiosRequestMake could be used as a generic HTTP proxy. The endpoint was reachable without authentication, and its URL-extension allowlist used a regular expression tested against the full URL string. This allowed attackers to bypass the restriction by appending .csv to the query string, enabling the NocoDB process to issue HTTP requests to arbitrary destinations, including internal services reachable from the host.
Recommendations Update to version 2026.05.1.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53931
GHSA-HMCR-RMJQ-47QR

Affected Products

Nocodb