← back
CVE-2026-52887criticalCWE-89

NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 10epss 0.6%
from disclosure to weapon19 days
Published on NVDJul 15
1st PoC+19d
exploitation probability
0.6%top 55% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal() template string without escaping or parameter binding, allowing a signed-up authenticated user to run stacked PostgreSQL statements and potentially execute commands with COPY ... TO PROGRAM. This vulnerability is fixed in 2.0.61.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
nocobase · nocobase
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.