CVE-2026-52887
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal() template string without escaping or parameter binding, allowing a signed-up authenticated user to run stacked PostgreSQL statements and potentially execute commands with COPY ... TO PROGRAM. This vulnerability is fixed in 2.0.61.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/nocobase/nocobase/releases/tag/v2.0.61, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/52xxx/CVE-2026-52887.json, https://github.com/nocobase/nocobase/security/advisories/GHSA-p849-8hwh-84j9, https://nvd.nist.gov/vuln/detail/CVE-2026-52887, https://github.com/nocobase/nocobase/commit/68d64e3fcfb8be2ae4f3bfc9e1ee3f85b87c89ce