CVE-2023-50718: Nocodb

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

NocoDB is software for building databases as spreadsheets. Prior to version 0.202.10, an authenticated attacker with create access could conduct a SQL Injection attack on MySQL DB using unescaped `table_name`. This vulnerability may result in leakage of sensitive data in the database. Version 0.202.10 contains a patch for the issue.

Affected products

  • Nocodb Nocodb: before 0.202.10 (fixed in 0.202.10)

Published 2024-05-14. Last modified 2026-06-17.