PT-2026-47086 · Git+2 · Nocodb

·

CVE-2026-47388

·

Published

2026-06-05

·

Updated

2026-06-25

CVSS v4.0

2.3

Low

VectorAV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions NocoDB versions prior to 2026.05.1
Description A low-privilege MCP token holder with knowledge of an attachment path can read any file in shared storage, including attachments from other bases and workspaces. This occurs because the MCP readAttachment() tool fails to verify file ownership, allowing the tool to stream files via the storage adapter using caller-supplied path or url variables without validating if the base id matches the caller's MCP context.
Recommendations Update to version 2026.05.1.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47388
GHSA-XXPJ-Q764-9R6Q

Affected Products

Nocodb