Executive brief
NocoDB is a self-hosted database management tool similar to Airtable. Organizations sharing database views with specific people or external stakeholders intended to hide certain columns from those shared views, but a design flaw allowed anyone with the shared view's UUID to bypass those restrictions. An attacker could directly read hidden columns, infer hidden data by observing row counts in filtered results, and access data from completely separate tables within the same database—all without needing to log in.
Technical details
The vulnerability stems from insufficient input validation in three independent code paths handling public shared-view requests. The groupBy endpoint fails to validate that requested column names exist in the visible column set, allowing direct enumeration. The filter and sort functionality operates on column references (fk_column_id) without checking visibility, enabling boolean-blind information disclosure. The related-data list endpoint accepts arbitrary link-column IDs without verifying the target table belongs to the current model, allowing cross-table data access. Attack preconditions require only possession of a valid shared-view UUID; no authentication or user interaction is needed. The fix (v2026.04.1) introduces sanitizeListArgsForPublicView to strip unsafe request keys, validates filter/sort operations against visible columns only, and enforces table-ownership checks on related-data resolution. CWE-639 (Authorization Bypass Through User-Controlled Key).
Affected products
- NocoDB nocodb < 2026.04.1
Timeline
- 2026-06-05: disclosed: GHSA advisory published
- 2026-04-01: patched: Fix released in version 2026.04.1