Executive brief
NocoDB is an open-source database management platform used to build collaborative applications. An attacker can craft a malicious password-reset link that executes arbitrary JavaScript in a victim's browser when clicked, potentially allowing session hijacking, credential theft, or account takeover.
Technical details
The vulnerability is a reflected cross-site scripting (XSS) flaw in the password reset endpoint /api/v1/db/auth/password/reset/:tokenId. The root cause is improper input sanitization in the EJS template engine (resetPassword.ts), which uses the insecure unescaped output tag "<%-" to render user-controlled token parameters without neutralization. An attacker can inject malicious JavaScript by crafting a reset link with encoded script tags in the tokenId parameter. The attack requires user interaction (victim must click a malicious link sent via email or social engineering) and does not require authentication. The vulnerability was fixed in version 0.258.0 by implementing proper output escaping.
Affected products
- NocoDB NocoDB < 0.258.0
Timeline
- 2025-03-06: disclosed
- 2025-03-06: patched: Fixed in version 0.258.0