Junglewise Threat Intelligence

CVE-2025-27506: NocoDB reflected cross-site scripting in password reset

CVE-2025-27506 · Severity: low · CVSS 3.1 · Published 2025-03-06

Technologies: nocodb (npm). Vendors: NocoDB, npm.

Executive brief

NocoDB is an open-source database management platform used to build collaborative applications. An attacker can craft a malicious password-reset link that executes arbitrary JavaScript in a victim's browser when clicked, potentially allowing session hijacking, credential theft, or account takeover.

Technical details

The vulnerability is a reflected cross-site scripting (XSS) flaw in the password reset endpoint /api/v1/db/auth/password/reset/:tokenId. The root cause is improper input sanitization in the EJS template engine (resetPassword.ts), which uses the insecure unescaped output tag "<%-" to render user-controlled token parameters without neutralization. An attacker can inject malicious JavaScript by crafting a reset link with encoded script tags in the tokenId parameter. The attack requires user interaction (victim must click a malicious link sent via email or social engineering) and does not require authentication. The vulnerability was fixed in version 0.258.0 by implementing proper output escaping.

Affected products

  • NocoDB NocoDB < 0.258.0

Timeline

  • 2025-03-06: disclosed
  • 2025-03-06: patched: Fixed in version 0.258.0

References

Related threats