Skip to content
Threat Feed

Vendor

Nocobase

5 briefs RSS
high advisory

NocoBase Authenticated Remote Code Execution via File Write and LFI Chain

An authenticated admin can achieve remote code execution in NocoBase prior to v2.1.5 by chaining arbitrary file uploads via storage root manipulation with a local file inclusion vulnerability in the plugin manager.

@nocobase/server remote-code-execution lfi nocobase authentication-bypass
1r 2t
critical advisory

NocoBase Authenticated SQL Injection to RCE

A critical SQL injection vulnerability in NocoBase allows authenticated attackers to achieve remote code execution on the underlying PostgreSQL container via stacked statements.

NocoBase server +1 webserver sql-injection rce authentication-bypass
1r 2t 1c
high advisory

NocoBase 2.0.27 VM Sandbox Escape Vulnerability

A local exploit has been published for NocoBase 2.0.27, detailing a VM Sandbox Escape vulnerability, increasing the risk to unpatched systems.

NocoBase 2.0.27 vm-sandbox-escape local-exploit nocobase
2r
high advisory

NocoBase SQL Injection via Missing Validation on Update Endpoint

A SQL injection vulnerability exists in nocobase plugin-collection-sql versions 2.0.32 and earlier due to missing validation on the sqlCollection:update endpoint, allowing attackers with collection management permissions to execute arbitrary SQL queries and exfiltrate data.

plugin-collection-sql sql-injection web-application nocobase
2r 1t
critical advisory

NocoBase SQL Injection via Recursive Eager Loading

NocoBase versions 2.0.32 and earlier are vulnerable to SQL injection due to string concatenation in the `queryParentSQL()` function, allowing attackers with record creation permissions to inject arbitrary SQL and potentially extract sensitive information or execute commands.

NocoBase sqli cve-2026-41640 injection
2r 4t