Executive brief
NocoDB is a popular open-source database management and collaboration platform. When a user resets their password, the application fails to revoke previously issued refresh tokens, allowing an attacker who previously stole a refresh token to continue accessing the account and generating valid authentication tokens until that stolen token naturally expires.
Technical details
The vulnerability is a session expiration weakness (CWE-613) in NocoDB's password reset flow. The passwordReset() function in users.service.ts increments the token_version field (which invalidates JWTs), but fails to call UserRefreshToken.deleteAllUserToken() to revoke refresh tokens. The refreshToken() method only validates token existence, not token_version compatibility. In contrast, passwordChange() and signOut() correctly delete all refresh tokens. An attacker with a previously stolen refresh token can exploit this to mint new valid JWTs after the victim resets their password, maintaining unauthorized access until the stolen refresh token's natural expiration. The patch is available in version 0.301.3.
Affected products
- NocoDB NocoDB <= 0.301.2
Timeline
- 2026-03-02: disclosed: Advisory published
- 2026-03-02: patched: Fix released in version 0.301.3