CVE-2026-41640Disclosure(nocobase / nocobase)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.39, the queryParentSQL() function in the core database package constructs a recursive CTE query by joining nodeIds with string concatenation instead of using parameterized queries. The nodeIds array contains primary key values read from database rows. An attacker who can create a record with a malicious string primary key can inject arbitrary SQL when any subsequent request triggers recursive eager loading on that collection. This issue has been patched in version 2.0.39.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nocobase

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-05-07)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
nocobase

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-23: 1Mentions · 2026-05-07: 3Technical Details · 2026-04-23: 1Technical Details · 2026-05-07: 304-2305-07
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-231
Disclosure1
2026-05-073
Disclosure3
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-41640 NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.39, the queryParentSQL() functio… https://www.cve.org/CVERecord?id=CVE-2026-41640

    Post summary

    The post announces a CVE affecting NocoBase prior to version 2.0.39, highlighting a potential issue in the queryParentSQL() function without providing PoC, exploit, or patch details.

    20010111
    57.4K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-41640 - high 🚨 NocoBase - SQL Injection > NocoBase versions prior to 2.0.39 contain a SQL injection vulnerability in the @nocob... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-41640 @pdnuclei #NucleiTemplates #cve

    Post summary

    The text announces a high-severity SQL injection vulnerability in NocoBase versions before 2.0.39.

    00021195
    942 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-41640 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-41640 #CVE-2026-41640 #CVE #High #CyberSecurity #InfoSec https://t.co/EnT0106jdK

    Post summary

    The tweet announces CVE-2026-41640 with severity 7.5 and high risk for multiple unspecified products, but offers no additional technical details, PoC, or patch information.

    0000043
    152 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41640 SQL Injection in NocoBase Prior to Version 2.0.39 via queryParentSQL() https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41640

    Post summary

    A new CVE (2026-41640) identifies an SQL injection vulnerability in NocoBase versions prior to 2.0.39 via queryParentSQL(), but no PoC, exploit code, or patch details are provided.

    0000041
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnocobasenocobase---

Explore more