← Voltar à pesquisa de CVEs

CVE-2026-52888

NocoBase

Descrição

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.59 and earlier, NocoBase @nocobase/plugin-collection-sql used the checkSQL() function in packages/plugins/@nocobase/plugin-collection-sql/src/server/utils.ts with an incomplete keyword blacklist that did not restrict PostgreSQL system catalog tables such as pg_shadow, pg_roles, and pg_stat_activity, allowing an admin-role user to read password hashes and database metadata through the SQL Collection feature. This vulnerability is fixed in 2.1.0-alpha.46.

CVSS 6.8EPSS 0.269%Risco 0.7
Ver fonte
Publicação
2026-07-15 21:16:54
Versões afetadas
<2.1.0-alpha.46
Tipo
Aplicação web
Vetor
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N