CVE-2026-41640

HIGH NUCLEI

NocoBase Vulnerable to SQL Injection via String Concatenation in Recursive Eager Loading

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-41640 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.39, the queryParentSQL() function in the core database package constructs a recursive CTE query by joining nodeIds with string concatenation instead of using parameterized queries. The nodeIds array contains primary key values read from database rows. An attacker who can create a record with a malicious string primary key can inject arbitrary SQL when any subsequent request triggers recursive eager loading on that collection. This issue has been patched in version 2.0.39.

Nuclei Templates (1)

NocoBase - SQL Injection
HIGHVERIFIEDby theamanrawat

Scores

CVSS v3 7.5
EPSS 0.0550
EPSS Percentile 90.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (2)
nocobase/database 0 - 2.0.39npm
nocobase/nocobase < 2.0.39 (2 CPE variants)
Published May 07, 2026
Tracked Since May 07, 2026