Executive brief
NocoDB is a popular open-source database management and collaboration platform. An authenticated attacker with org-level-creator permissions can trigger a prototype pollution vulnerability in the connection test endpoint, causing all database write operations to fail application-wide until the server is restarted. This results in a complete denial of service for data modification capabilities across all users.
Technical details
The vulnerability is a prototype pollution issue in the deepMerge() function (packages/nocodb/src/utils/dataUtils.ts) which fails to sanitize dangerous keys such as __proto__, constructor, and prototype. The /api/v2/meta/connection/test endpoint passes user-controlled input directly to this function without validation. An authenticated attacker with org-level-creator permissions can send a malicious payload like {"__proto__": {"super": true}} to pollute Object.prototype globally, affecting all plain objects in the Node.js process. The result is that all subsequent database write operations fail for all users until the server restarts. While the pollution technically bypasses authorization checks, no privilege escalation occurs because write operations fail immediately. The vulnerability was fixed in version 0.301.0.
Affected products
- NocoDB NocoDB <= 0.265.1 (fixed in 0.301.0)
Timeline
- 2026-01-28: disclosed: Advisory published
- 2026-01-28: patched: Fix released in version 0.301.0