CVE-2026-24766
MEDIUMNocodb < 0.301.0 - Prototype Pollution
Title source: ruleDescription
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, an authenticated user with org-level-creator permissions can exploit prototype pollution in the `/api/v2/meta/connection/test` endpoint, causing all database write operations to fail application-wide until server restart. While the pollution technically bypasses SUPER_ADMIN authorization checks, no practical privileged actions can be performed because database operations fail immediately after pollution. Version 0.301.0 patches the issue.
Scores
CVSS v3
4.9
EPSS
0.0012
EPSS Percentile
31.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-1321
Status
published
Affected Products (2)
nocodb/nocodb
< 0.301.0
npm/nocodb
< 0.301.0npm
Timeline
Published
Jan 28, 2026
Tracked Since
Feb 18, 2026