CVE-2026-52888

MEDIUM

NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass

Title source: cna
STIX 2.1

Description

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.59 and earlier, NocoBase @nocobase/plugin-collection-sql used the checkSQL() function in packages/plugins/@nocobase/plugin-collection-sql/src/server/utils.ts with an incomplete keyword blacklist that did not restrict PostgreSQL system catalog tables such as pg_shadow, pg_roles, and pg_stat_activity, allowing an admin-role user to read password hashes and database metadata through the SQL Collection feature. This vulnerability is fixed in 2.1.0-alpha.46.

Scores

CVSS v3 6.8
EPSS 0.0027
EPSS Percentile 19.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-184 CWE-200
Status published
Products (4)
nocobase/nocobase < 2.1.0-alpha.46
nocobase/plugin-collection-sql 0 - 2.0.62npm
nocobase/plugin-collection-sql 2.1.0-alpha.1 - 2.1.0-alpha.46npm
nocobase/plugin-collection-sql 2.1.0-beta.1 - 2.1.0-beta.45npm
Published Jul 15, 2026
Tracked Since Jul 16, 2026