Medium severityNVD Advisory· Published Jun 23, 2026· Updated Jun 25, 2026
CVE-2026-53931
CVE-2026-53931
Description
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the spreadsheet-import endpoint axiosRequestMake could be used as a generic HTTP proxy. Before the fix it was reachable unauthenticated, and its URL-extension allowlist was a regex tested against the full URL string, so URLs whose query string ended in .csv satisfies the gate even though the underlying request is for another file. This vulnerability is fixed in 2026.05.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nocodbnpm | <= 0.301.3 | — |
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
1- NocoDB: Five CVEs Disclosed Together — Unauthenticated SSRF, Stored XSS, and Token Persistence FlawVypr Intelligence · Jun 17, 2026