Executive brief
NocoDB, a platform for building databases as spreadsheets, failed to properly cancel active login sessions when a user changed or reset their password. This means that if an attacker had already gained access to an account via an OAuth token, they would remain logged in even after the legitimate user updated their security credentials. This could lead to unauthorized data access and persistent account compromise despite the user's attempts to secure their account.
Technical details
A vulnerability exists in NocoDB where the 'revokeAllOAuthTokensByUser' function in the users service was implemented as an empty stub. Consequently, when security events such as passwordChange, passwordForgot, or passwordReset were triggered, existing OAuth access and refresh tokens remained valid. An attacker with a previously issued OAuth grant could maintain persistent access to the user's account even after a password reset. The fix, introduced in version 2026.05.1, implements proper delegation to 'OAuthToken.revokeAllByUser' to delete relevant database rows and invalidate authentication caches.
Affected products
- nocodb nocodb < 2026.05.1
Timeline
- 2026-06-04: advisory: GitHub Security Advisory published
- 2026-06-23: disclosed: CVE published to NVD