{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/@nocobase/plugin-notification-in-app-message/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":10,"id":"CVE-2026-52887"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NocoBase server","@nocobase/plugin-notification-in-app-message"],"_cs_severities":["critical"],"_cs_tags":["webserver","sql-injection","rce","authentication-bypass"],"_cs_type":"advisory","_cs_vendors":["NocoBase"],"content_html":"\u003cp\u003eNocoBase versions 2.0.60 and earlier contain a critical SQL injection vulnerability in the \u003ccode\u003e/api/myInAppChannels:list\u003c/code\u003e endpoint. The vulnerability arises because the \u003ccode\u003elatestMsgReceiveTimestamp\u003c/code\u003e filter parameter is unsafely interpolated into a \u003ccode\u003eSequelize.literal()\u003c/code\u003e template string without proper escaping or parameter binding. Because NocoBase defaults to allowing anonymous account registration (\u003ccode\u003eallowSignUp: true\u003c/code\u003e), any unauthenticated attacker can create an account and access this endpoint.\u003c/p\u003e\n\u003cp\u003eThe application utilizes the \u003ccode\u003epg\u003c/code\u003e driver, which supports stacked SQL statements. Coupled with the default PostgreSQL container configuration where the \u003ccode\u003enocobase\u003c/code\u003e database user is granted superuser privileges (\u003ccode\u003erolsuper=true\u003c/code\u003e), an attacker can execute arbitrary system commands using the \u003ccode\u003eCOPY ... TO PROGRAM\u003c/code\u003e syntax. This vulnerability leads to full database compromise, including sensitive data exfiltration (such as administrator password hashes) and remote code execution within the database container.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker interacts with the \u003ccode\u003e/api/auth:signUp\u003c/code\u003e endpoint to create a new user account, exploiting the default \u003ccode\u003eallowSignUp: true\u003c/code\u003e configuration.\u003c/li\u003e\n\u003cli\u003eAttacker performs an authentication request to \u003ccode\u003e/api/auth:signIn\u003c/code\u003e to obtain a valid \u003ccode\u003emember\u003c/code\u003e role JSON Web Token (JWT).\u003c/li\u003e\n\u003cli\u003eAttacker identifies the vulnerable \u003ccode\u003efilter[latestMsgReceiveTimestamp][$lt]\u003c/code\u003e parameter on the \u003ccode\u003e/api/myInAppChannels:list\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker validates the injection point using a time-based oracle payload (e.g., \u003ccode\u003ePG_SLEEP(5)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP GET request containing a stacked-statement SQL payload using \u003ccode\u003eCOPY ... TO PROGRAM\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe backend database executes the injected command with the privileges of the \u003ccode\u003epostgres\u003c/code\u003e system user (uid 999).\u003c/li\u003e\n\u003cli\u003eAttacker achieves command execution and can exfiltrate sensitive collections or system data from the host container.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to gain full access to the NocoBase database. The impact includes the exfiltration of sensitive information, such as administrator credentials (stored as PBKDF2 hashes), and remote code execution within the database container, which may facilitate lateral movement or further environment compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade NocoBase to version 2.0.61 or later immediately.\u003c/li\u003e\n\u003cli\u003eDisable anonymous sign-ups by modifying the \u003ccode\u003eauth-basic\u003c/code\u003e configuration if registration is not required.\u003c/li\u003e\n\u003cli\u003eReview database role privileges and ensure the PostgreSQL user configured for NocoBase follows the principle of least privilege rather than running as a superuser.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect anomalous requests to the \u003ccode\u003e/api/myInAppChannels:list\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-31T19:45:24Z","date_published":"2026-07-31T19:45:24Z","id":"https://feed.craftedsignal.io/briefs/2026-07-nocobase-sql-rce/","summary":"A critical SQL injection vulnerability in NocoBase allows authenticated attackers to achieve remote code execution on the underlying PostgreSQL container via stacked statements.","title":"NocoBase Authenticated SQL Injection to RCE","url":"https://feed.craftedsignal.io/briefs/2026-07-nocobase-sql-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - @Nocobase/Plugin-Notification-in-App-Message","version":"https://jsonfeed.org/version/1.1"}