Vulnerability Description
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal() template string without escaping or parameter binding, allowing a signed-up authenticated user to run stacked PostgreSQL statements and potentially execute commands with COPY ... TO PROGRAM. This vulnerability is fixed in 2.0.61.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/nocobase/nocobase/commit/68d64e3fcfb8be2ae4f3bfc9e1ee3f85b87c
- https://github.com/nocobase/nocobase/releases/tag/v2.0.61
- https://github.com/nocobase/nocobase/security/advisories/GHSA-p849-8hwh-84j9
- https://github.com/nocobase/nocobase/security/advisories/GHSA-p849-8hwh-84j9
FAQ
What is CVE-2026-52887?
CVE-2026-52887 is a vulnerability with a CVSS score of 10.0 (CRITICAL). NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api...
How severe is CVE-2026-52887?
CVE-2026-52887 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-52887?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.