VYPR
Medium severityNVD Advisory· Published Jun 23, 2026· Updated Jun 25, 2026

CVE-2026-47377

CVE-2026-47377

Description

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the client-side hashRedirect plugin called window.location.replace() on a path extracted from the URL hash fragment after only checking hashPath.startsWith('/'). Protocol-relative URLs (//attacker.com/…) also satisfy that check, so a crafted link silently redirected visitors to an attacker-controlled origin. This vulnerability is fixed in 2026.04.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
nocodbnpm
< 2026.04.12026.04.1

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

1