{"id":"CVE-2026-34825","aliases":["GHSA-vx58-fwwq-5g8j"],"url":"https://o3.security/vulnerability/CVE-2026-34825","summary":"NocoBase Has SQL Injection via template variable substitution in workflow SQL node","details":"NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.30, NocoBase plugin-workflow-sql substitutes template variables directly into raw SQL strings via getParsedValue() without parameterization or escaping. Any user who triggers a workflow containing a SQL node with template variables from user-controlled data can inject arbitrary SQL. This issue has been patched in version 2.0.30.","published":"2026-04-02T19:06:07.592Z","modified":"2026-08-07T11:50:58.721366509Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@nocobase/plugin-workflow-sql","fixedVersion":"2.0.30"}],"fix":{"url":"https://github.com/nocobase/nocobase/commit/75da3dddc4aba739c398f7072725dcf7f5487f5c","label":"nocobase/nocobase@75da3dd"},"references":[{"type":"WEB","url":"https://github.com/nocobase/nocobase/releases/tag/v2.0.30"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34825.json"},{"type":"ADVISORY","url":"https://github.com/nocobase/nocobase/security/advisories/GHSA-vx58-fwwq-5g8j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34825"},{"type":"FIX","url":"https://github.com/nocobase/nocobase/commit/75da3dddc4aba739c398f7072725dcf7f5487f5c"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:50:58.721366509Z"}}