Junglewise Threat Intelligence

CVE-2026-47376: NocoDB reflected XSS in password-reset page

CVE-2026-47376 · Severity: medium · CVSS 4 · Published 2026-06-23

Technologies: nocodb (npm). Vendors: NocoDB, npm.

Executive brief

NocoDB is an open-source platform that turns databases into smart spreadsheets. A security flaw in the password reset process allows attackers to run malicious code in a user's browser if the user clicks a specially crafted link. This could allow an attacker to perform actions on behalf of the user or access sensitive session information.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in NocoDB's password-reset page due to improper neutralization of input. The application used an EJS template to render a URL token directly into a JavaScript string literal using the `<%= %>` tag. While this tag HTML-entity encodes some characters, it fails to escape single quotes or backslashes, allowing an attacker to break out of the string context. An attacker can craft a malicious password-reset link that, when clicked by a victim, executes arbitrary JavaScript in the context of the NocoDB origin. This can be used to steal authentication tokens or perform unauthorized actions. The issue is resolved in version 2026.04.1 by moving the token to an HTML data attribute.

Affected products

  • NocoDB NocoDB < 2026.04.1

Timeline

  • 2026-06-04: advisory: GitHub Security Advisory published
  • 2026-06-23: disclosed: CVE published to NVD
  • 2026.04.1: patched

References

Related threats