๐Ÿ” CVE Alert

CVE-2026-47378

UNKNOWN 0.0

NocoDB: Hidden Column Exposure in Public Shared View Endpoints

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, Public shared-view endpoints exposed values from columns that the view owner had hidden, via three independent paths: groupBy returned raw values for any column named in the request, filter and sort arrays operated on hidden columns enabling boolean-blind extraction, and the related-data list accepted arbitrary link-column IDs from other tables in the same base. This vulnerability is fixed in 2026.04.1.

CWE CWE-639
Vendor nocodb
Product nocodb
Published Jun 23, 2026
Stay Ahead of the Next One

Get instant alerts for nocodb nocodb

Be the first to know when new unknown vulnerabilities affecting nocodb nocodb are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

nocodb / nocodb
< 2026.04.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/nocodb/nocodb/security/advisories/GHSA-4w6r-5c2j-qf5f