Executive brief
NocoDB is a popular open-source database management and collaboration platform. A stored cross-site scripting vulnerability in the comments feature allows users with the Commenter role to inject malicious scripts that execute for all users viewing those comments, potentially compromising account security and enabling unauthorized actions on behalf of affected users.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in the Comments.vue component where comments are parsed by markdown-it with the html option enabled and then injected into the DOM via v-html without sanitization using DOMPurify. An unauthenticated attacker or a user with Commenter role can inject arbitrary HTML and JavaScript code that persists in the database and executes in the browsers of all subsequent viewers. The attack vector is network-based, requires only the ability to post a comment, and no special privileges beyond basic user interaction. The vulnerability has been fixed in version 0.301.3.
Affected products
- NocoDB NocoDB <= 0.301.2
Timeline
- 2026-03-03: disclosed: GHSA published
- 2026-03-03: patched: Fixed in version 0.301.3