Executive brief
NocoDB, an open-source platform that turns databases into smart spreadsheets, failed to properly revoke OAuth access and refresh tokens during security events like password changes or resets. This means that if an attacker had previously gained access to a user's account via an OAuth grant, they would maintain that access even after the legitimate user changed their password to lock them out. This could lead to persistent unauthorized access to sensitive business data stored within the platform.
Technical details
NocoDB suffered from insufficient session expiration (CWE-613) because the 'revokeAllOAuthTokensByUser' function in the users service was an empty stub. This function was called during 'passwordChange', 'passwordForgot', and 'passwordReset' flows but failed to perform any action. Consequently, OAuth access and refresh tokens remained active in the database and cache after these security events. An attacker with a previously issued token could maintain persistent unauthorized access despite the user's attempt to secure the account. The fix involves delegating the call to 'OAuthToken.revokeAllByUser', which properly deletes token rows, invalidates auth caches, and rotates the 'token_version'. This issue is patched in version 2026.05.1.
Affected products
- nocodb nocodb <= 2026.05.0
Timeline
- 2026-06-04: disclosed
- 2026-06-05: advisory
- 2026-05-01: patched: Patched in version 2026.05.1
References
- https://api.github.com/users/bugbunny-research
- https://github.com/bugbunny-research
- https://api.github.com/users/bugbunny-research/gists%7B/gist_id%7D
- https://api.github.com/users/bugbunny-research/repos
- https://avatars.githubusercontent.com/u/262839898?v=4
- https://api.github.com/users/bugbunny-research/events%7B/privacy%7D