CVE Explorer
CVE-2026-24767
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a blind Server-Side Request Forgery (SSRF) vulnerability exists in the `uploadViaURL` functionality due to an unprotected `HEAD` request. While the subsequent file retrieval logic correctly enforces SSRF protections, the initial metadata request executes without validation. This allows limited outbound requests to arbitrary URLs before SSRF controls are applied. Version 0.301.0 contains a patch for the issue.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"nocodb","vendor":"nocodb","versions":[{"status":"affected","version":"< 0.301.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:96717ab2bd46370a0c6e912f336f857e1ddd6d63ecc10cc50977f8d7d08a6d66 · sha256:5827e29d1bb6311a… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.9,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:96717ab2bd46370a0c6e912f336f857e1ddd6d63ecc10cc50977f8d7d08a6d66 · sha256:5827e29d1bb6311a… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-918","description":"CWE-918: Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:96717ab2bd46370a0c6e912f336f857e1ddd6d63ecc10cc50977f8d7d08a6d66 · sha256:5827e29d1bb6311a… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/nocodb/nocodb/security/advisories/GHSA-xr7v-j379-34v9","tags":["x_refsource_CONFIRM"],"url":"https://github.com/nocodb/nocodb/security/advisories/GHSA-xr7v-j379-34v9"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:96717ab2bd46370a0c6e912f336f857e1ddd6d63ecc10cc50977f8d7d08a6d66 · sha256:5827e29d1bb6311a… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/nocodb/nocodb/security/advisories/GHSA-xr7v-j379-34v9"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:96717ab2bd46370a0c6e912f336f857e1ddd6d63ecc10cc50977f8d7d08a6d66 · sha256:5827e29d1bb6311a… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.