Home

Description

NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password forgot endpoint returned different responses for registered and unregistered emails, allowing user enumeration. This issue has been patched in version 0.301.3.

PUBLISHED Reserved 2026-02-26 | Published 2026-03-02 | Updated 2026-03-03 | Assigner GitHub_M




LOW: 2.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U

Problem types

CWE-204: Observable Response Discrepancy

Product status

< 0.301.3
affected

References

github.com/...nocodb/security/advisories/GHSA-387m-j3p9-3php

github.com/nocodb/nocodb/releases/tag/0.301.3

cve.org (CVE-2026-28358)

nvd.nist.gov (CVE-2026-28358)

Download JSON