User Impersonation Affecting nocodb package, versions <0.301.3


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.1% (28th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-NOCODB-17337659
  • published14 Jun 2026
  • disclosed5 Jun 2026
  • creditFullmoon

Introduced: 5 Jun 2026

NewCVE-2026-47381  (opens in a new tab)
CWE-290  (opens in a new tab)

How to fix?

Upgrade nocodb to version 0.301.3 or higher.

Overview

nocodb is a NocoDB

Affected versions of this package are vulnerable to User Impersonation via the testConnection endpoint when the integration is fetched in a bypass scope and permission checks are insufficiently scoped to the integration's workspace. An attacker can gain unauthorized access to integration configurations and potentially interact with databases using another workspace's credentials by supplying the integration ID and possessing creator or owner privileges on any base in any workspace.

CVSS Base Scores

version 4.0
version 3.1