Junglewise Threat Intelligence

CVE-2026-28357: NocoDB stored cross-site scripting in Formula cell

CVE-2026-28357 · Severity: medium · CVSS 4 · Published 2026-03-02

Technologies: nocodb (npm). Vendors: NocoDB, npm.

Executive brief

NocoDB is a popular open-source database management platform. A stored XSS vulnerability in the Formula cell feature allows users with Creator role to inject malicious scripts that execute in the browsers of anyone viewing the affected table, potentially leading to credential theft and account compromise.

Technical details

A stored XSS vulnerability exists in NocoDB's Formula virtual cell implementation. The replaceUrlsWithLink() function in urlUtils.ts converts URI::(url) patterns to anchor tags but fails to sanitize other HTML content, which is then rendered via v-html without additional sanitization. An attacker with Creator role can craft a formula containing both URI::() patterns and malicious HTML tags (e.g., CONCAT("URI::(https://example.com)", "<img src=x onerror=...>")) to inject arbitrary scripts. These scripts execute in the context of all users viewing the affected table. The vulnerability is stored in the database and affects all subsequent viewers. The issue was patched in version 0.301.3.

Affected products

  • NocoDB NocoDB <= 0.301.2

Timeline

  • 2026-03-02: disclosed
  • 2026-03-02: patched: Fixed in version 0.301.3

References

Related threats