VYPR
Moderate severityNVD Advisory· Published Jul 15, 2026· Updated Jul 16, 2026

NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass

CVE-2026-52888

Description

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.59 and earlier, NocoBase @nocobase/plugin-collection-sql used the checkSQL() function in packages/plugins/@nocobase/plugin-collection-sql/src/server/utils.ts with an incomplete keyword blacklist that did not restrict PostgreSQL system catalog tables such as pg_shadow, pg_roles, and pg_stat_activity, allowing an admin-role user to read password hashes and database metadata through the SQL Collection feature. This vulnerability is fixed in 2.1.0-alpha.46.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@nocobase/plugin-collection-sqlnpm
< 2.0.622.0.62
@nocobase/plugin-collection-sqlnpm
>= 2.1.0-alpha.1, < 2.1.0-alpha.462.1.0-alpha.46
@nocobase/plugin-collection-sqlnpm
>= 2.1.0-beta.1, < 2.1.0-beta.452.1.0-beta.45

Affected products

2

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.