Medium severityNVD Advisory· Published Jun 23, 2026· Updated Jun 25, 2026
CVE-2026-53927
CVE-2026-53927
Description
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the spreadsheet-fetch endpoint (axiosRequestMake) accepted URLs whose path contained a permitted extension anywhere in the string, and applied a hand-rolled regex blocklist that omitted 127.0.0.0/8 and 169.254.0.0/16, allowing the cloud-metadata endpoint to be reached with a crafted URL This vulnerability is fixed in 2026.05.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nocodbnpm | <= 0.301.3 | — |
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
1- NocoDB: Five CVEs Disclosed Together — Unauthenticated SSRF, Stored XSS, and Token Persistence FlawVypr Intelligence · Jun 17, 2026