CVE-2022-22121: high-severity vulnerability in nocodb
NocoDB - CSV Injection in User Management
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8epss 1.2%
exploitation probability
1.2%top 33% of all CVEs
observed exploitation
nono source reports it
In short
NocoDB allows attackers to inject malicious code into CSV files through table data. When an admin exports and opens the file in a spreadsheet application, the code executes automatically, potentially compromising the admin's system.
Technical detail
CSV injection vulnerability in NocoDB 0.81.0–0.83.8 allows low-privileged users to inject formula payloads into table rows. When administrators export user management data as CSV and open it in spreadsheet applications, the formulas execute with admin privileges, enabling arbitrary code execution or data exfiltration.
Summary generated and translated by AI from the official description.
In NocoDB, versions 0.81.0 through 0.83.8 are affected by CSV Injection vulnerability (Formula Injection). A low privileged attacker can create a new table to inject payloads in the table rows. When an administrator accesses the User Management endpoint and exports the data as a CSV file and opens it, the payload gets executed.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Affected products
nocodb · nocodbRelated CVEs — nocodb
In the same product, most dangerous first.
CVE-2022-22120MEDIUMNocoDB - Observable Discrepancy in the password-reset featureEPSS 1.4%CVE-2023-43794MEDIUMSQL Injection in nocodbEPSS 0.8%CVE-2026-28358LOWNocoDB: User Enumeration via Password Reset EndpointEPSS 0.7%CVE-2025-27506MEDIUMNocoDB Vulnerable to Reflected Cross-Site Scripting on Reset Password PageEPSS 0.7%CVE-2023-50718MEDIUMNocoDB SQL Injection vulnerabilityEPSS 0.7%CVE-2023-49781HIGHNocoDB Vulnerable to Stored Cross-Site Scripting in Formula.vueEPSS 0.6%