Executive brief
NocoDB is an open-source platform that turns databases into easy-to-use spreadsheets. A security flaw in how the application handles login sessions could allow attackers to intercept user credentials over unencrypted connections or trick a user's browser into performing unauthorized actions. This could lead to unauthorized access to sensitive database information or account takeover.
Technical details
NocoDB versions prior to 2026.04.1 fail to apply the 'Secure' flag and 'SameSite' attribute to the refresh-token cookie in the 'setTokenCookie' helper. Because the 'Secure' flag is missing, the cookie can be transmitted over unencrypted HTTP, making it vulnerable to network interception. Additionally, the absence of the 'SameSite' attribute allows browsers to include the cookie in cross-site POST requests, facilitating a Cross-Site Request Forgery (CSRF) attack against the '/api/v2/auth/token/refresh' endpoint. An attacker could potentially refresh a victim's session and, if combined with other vulnerabilities like XSS, capture the new JWT. The issue is resolved in version 2026.04.1 by implementing 'SameSite: lax' and conditional 'Secure' flags.
Affected products
- NocoDB NocoDB < 2026.04.1
Timeline
- 2026-05-19: advisory: GitHub Security Advisory published
- 2026-06-23: disclosed: CVE published to NVD
- 2026-04-01: patched: Fix released in version 2026.04.1