{"id":"CVE-2026-41640","aliases":["GHSA-4948-f92q-f432"],"url":"https://o3.security/vulnerability/CVE-2026-41640","summary":"NocoBase Vulnerable to SQL Injection via String Concatenation in Recursive Eager Loading","details":"NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.39, the queryParentSQL() function in the core database package constructs a recursive CTE query by joining nodeIds with string concatenation instead of using parameterized queries. The nodeIds array contains primary key values read from database rows. An attacker who can create a record with a malicious string primary key can inject arbitrary SQL when any subsequent request triggers recursive eager loading on that collection. This issue has been patched in version 2.0.39.","published":"2026-05-07T04:09:59.264Z","modified":"2026-08-07T11:51:03.948489991Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@nocobase/database","fixedVersion":"2.0.39"}],"fix":{"url":"https://github.com/nocobase/nocobase/commit/202e2b8efe44ba90adbf1087f6f70881ff947604","label":"nocobase/nocobase@202e2b8"},"references":[{"type":"WEB","url":"https://github.com/nocobase/nocobase/releases/tag/v2.0.39"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41640.json"},{"type":"ADVISORY","url":"https://github.com/nocobase/nocobase/security/advisories/GHSA-4948-f92q-f432"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41640"},{"type":"FIX","url":"https://github.com/nocobase/nocobase/commit/202e2b8efe44ba90adbf1087f6f70881ff947604"},{"type":"FIX","url":"https://github.com/nocobase/nocobase/pull/9133"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:51:03.948489991Z"}}