Executive brief
NocoDB is an open-source database management platform used for building and sharing databases. A vulnerability in its MCP (Model Control Protocol) token service allows users with Creator role to view, regenerate, or delete other users' authentication tokens within the same base, potentially exposing sensitive credentials or disrupting service access for other team members.
Technical details
The McpTokenService.get(), regenerateToken(), and delete() functions did not filter operations by the fk_user_id field, failing to enforce ownership validation. This authorization bypass (CWE-639) allows a Creator-role user to manipulate MCP tokens belonging to other users if the token ID is known, whereas the analogous ApiTokensService correctly enforced ownership checks. Attack requires network access to NocoDB, Creator role within a shared base, and knowledge of the target token ID. An attacker can achieve token disclosure (reading scoped credentials) or denial of service (invalidating tokens). The vulnerability was patched in version 0.301.3.
Affected products
- NocoDB NocoDB <= 0.301.2
Timeline
- 2026-03-02: disclosed
- 2026-03-02: patched: version 0.301.3 released