{"id":"CVE-2026-52887","aliases":["GHSA-p849-8hwh-84j9"],"url":"https://o3.security/vulnerability/CVE-2026-52887","summary":"NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE","details":"NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal() template string without escaping or parameter binding, allowing a signed-up authenticated user to run stacked PostgreSQL statements and potentially execute commands with COPY ... TO PROGRAM. This vulnerability is fixed in 2.0.61.","published":"2026-07-15T20:16:43.023Z","modified":"2026-08-12T03:51:32.818659682Z","cvss":{"score":10,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"epss":{"score":0.00892,"percentile":0.57429,"asOf":"2026-09-13"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@nocobase/plugin-notification-in-app-message","fixedVersion":"2.0.61"}],"fix":{"url":"https://github.com/nocobase/nocobase/commit/68d64e3fcfb8be2ae4f3bfc9e1ee3f85b87c89ce","label":"nocobase/nocobase@68d64e3"},"references":[{"type":"WEB","url":"https://github.com/nocobase/nocobase/releases/tag/v2.0.61"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/52xxx/CVE-2026-52887.json"},{"type":"ADVISORY","url":"https://github.com/nocobase/nocobase/security/advisories/GHSA-p849-8hwh-84j9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-52887"},{"type":"FIX","url":"https://github.com/nocobase/nocobase/commit/68d64e3fcfb8be2ae4f3bfc9e1ee3f85b87c89ce"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:32.818659682Z"}}