CVE-2026-24766

MEDIUM

Nocodb < 0.301.0 - Prototype Pollution

Title source: rule

Description

NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, an authenticated user with org-level-creator permissions can exploit prototype pollution in the `/api/v2/meta/connection/test` endpoint, causing all database write operations to fail application-wide until server restart. While the pollution technically bypasses SUPER_ADMIN authorization checks, no practical privileged actions can be performed because database operations fail immediately after pollution. Version 0.301.0 patches the issue.

Scores

CVSS v3 4.9
EPSS 0.0012
EPSS Percentile 31.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-1321
Status published

Affected Products (2)

nocodb/nocodb < 0.301.0
npm/nocodb < 0.301.0npm

Timeline

Published Jan 28, 2026
Tracked Since Feb 18, 2026