Executive brief
NocoBase is an open-source data management and workflow platform. Two chained vulnerabilities allow an authenticated administrator to write malicious files to arbitrary locations on disk and then execute them as code, resulting in complete server compromise. This requires valid admin credentials but leads to full remote code execution with the privileges of the NocoBase process.
Technical details
The vulnerability chain consists of two flaws: (1) The storages:update API endpoint fails to validate the documentRoot parameter, allowing an authenticated admin to redirect the file upload storage root to any absolute filesystem path, including the application directory. An upload to this redirected root then writes a malicious payload anywhere the Node.js process can write. (2) The pm:enable plugin manager endpoint passes user-supplied paths directly to Node.js require() without validation, enabling local file inclusion. By uploading a malicious JavaScript file via the redirected storage and then triggering require() on its path, an attacker executes arbitrary code. Both vulnerabilities require admin authentication, and a working proof-of-concept exploit chain has been demonstrated. Patches are available in version 2.1.5 and later.
Affected products
- NocoBase NocoBase <2.1.5
Timeline
- 2026-06-15: disclosed
- 2026-06-15: patched: Fixed in version 2.1.5