
CVE-2026-24769: No-Code, Yes-Exploit: Weaponizing SVGs in NocoDB A critical Stored Cross-Site Scripting (XSS) vulnerability in NocoDB allows authenticated attackers to upload malicious SVG attachments. Due to lax MIME type checking and unsafe content ... https://cvereports.com/reports/CVE-2026-24769
Post summary
The post details a critical stored XSS in NocoDB that lets authenticated users upload malicious SVG files via weak MIME checks, but it does not provide a PoC, exploit code, or patch information.

