Junglewise Threat Intelligence

CVE-2026-53929: NocoDB stored cross-site scripting in secure attachments

CVE-2026-53929 · Severity: medium · CVSS 4 · Published 2026-06-23

Technologies: nocodb (npm). Vendors: NocoDB, npm.

Executive brief

NocoDB, a platform that turns databases into smart spreadsheets, is vulnerable to a security flaw when handling file attachments. An authorized user could upload malicious files (like HTML or SVG) that, when opened by another user, execute code within their browser. This could allow an attacker to steal login tokens or perform actions on behalf of other users, potentially compromising sensitive data stored in the database.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in NocoDB prior to version 2026.05.1 when NC_SECURE_ATTACHMENTS is enabled. The vulnerability is caused by a case-sensitivity mismatch in response-header overrides: the signed attachment handler stores keys in PascalCase (e.g., ResponseContentDisposition), while the serving controller attempts to read them using lowercase-hyphenated names (e.g., response-content-disposition). This mismatch causes the 'Content-Disposition: attachment' header to be dropped, leading the Express framework to render .html and .svg files inline. An authenticated attacker can exploit this to execute arbitrary JavaScript in the context of the NocoDB origin and steal authentication JWTs from localStorage. The issue is fixed in version 2026.05.1 by correcting the key casing and enforcing strict MIME types for non-previewable files.

Affected products

  • nocodb nocodb < 2026.05.1

Timeline

  • 2026-06-13: advisory: GitHub Security Advisory published
  • 2026-06-23: disclosed: CVE published to NVD

References

Related threats