VYPR

npm package

@nocobase/plugin-collection-sql

pkg:npm/%40nocobase/plugin-collection-sql

Vulnerabilities (1)

  • CVE-2026-41641HigMay 7, 2026
    affected < 2.0.39fixed 2.0.39

    NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.39, the checkSQL() validation function that blocks dangerous SQL keywords (e.g., pg_read_file, LOAD_FILE, dblink) is applied on the collections:cr