Junglewise Threat Intelligence

CVE-2026-53927: NocoDB SSRF in spreadsheet-fetch endpoint

CVE-2026-53927 · Severity: medium · CVSS 4 · Published 2026-06-23

Technologies: nocodb (npm). Vendors: NocoDB, npm.

Executive brief

NocoDB, a platform for building databases as spreadsheets, contains a security flaw in its spreadsheet import feature. An attacker with editor permissions can trick the system into making requests to internal servers or cloud metadata services that should be private. This could allow an attacker to steal sensitive cloud credentials or access internal network resources, potentially leading to a broader breach of the hosting environment.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the NocoDB spreadsheet-fetch endpoint (axiosRequestMake). The vulnerability stems from two flaws: a non-anchored regex that allowed permitted file extensions (like .xlsx) to appear anywhere in the URL path, and an incomplete IP blocklist that failed to restrict access to loopback (127.0.0.0/8) and link-local (169.254.0.0/16) addresses. An authenticated attacker with high privileges (Editor) can provide a crafted URL to bypass these checks and reach internal endpoints, including cloud metadata services. This can result in the exfiltration of sensitive environment credentials. The issue is resolved in version 2026.05.1 by implementing anchored extension matching and using a robust request-filtering agent to block private IP ranges at the socket layer.

Affected products

  • NocoDB NocoDB < 2026.05.1

Timeline

  • 2026-06-13: advisory: GitHub Security Advisory published
  • 2026-06-23: disclosed: CVE published to NVD
  • 2026-05-01: patched: Approximate date based on version number 2026.05.1

References

Related threats