Critical severityNVD Advisory· Published Jul 15, 2026· Updated Jul 20, 2026
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
CVE-2026-52887
Description
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal() template string without escaping or parameter binding, allowing a signed-up authenticated user to run stacked PostgreSQL statements and potentially execute commands with COPY ... TO PROGRAM. This vulnerability is fixed in 2.0.61.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@nocobase/plugin-notification-in-app-messagenpm | < 2.0.61 | 2.0.61 |
Affected products
1Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-p849-8hwh-84j9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-52887ghsaADVISORY
- github.com/nocobase/nocobase/commit/68d64e3fcfb8be2ae4f3bfc9e1ee3f85b87c89ceghsax_refsource_MISCWEB
- github.com/nocobase/nocobase/pull/9630ghsaWEB
- github.com/nocobase/nocobase/releases/tag/v2.0.61ghsax_refsource_MISCWEB
- github.com/nocobase/nocobase/security/advisories/GHSA-p849-8hwh-84j9ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.