/Vulnerability Library

NocoBase - SQL Injection

CVE-2026-41641
Verified

Description

NocoBase @nocobase/plugin-collection-sql versions prior to 2.0.39 are vulnerable to SQL injection via the sqlCollection:update endpoint. The checkSQL() function, which blocks dangerous SQL keywords and ensures only SELECT statements are allowed, is not called during collection updates.

Severity

High

CVSS Score

7.2

Exploit Probability

2%

Affected Product

nocobase

Published Date

April 23, 2026

Template Author

theamanrawat

CVE-2026-41641.yaml
7.2Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-41641
CWE ID:
cwe-89

References

https://github.com/advisories/GHSA-wrwh-c28m-9jjhhttps://nvd.nist.gov/vuln/detail/CVE-2026-41641

Remediation Steps

Upgrade NocoBase to version 2.0.39 or later