CRITICAL 10.0 GitHub
CVE-2026-52887
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
## Summary
`GET /api/myInAppChannels:list` accepts a structured `filter` query parameter. The handler for the `latestMsgReceiveTimestamp` field splices the `$lt` value directly into a `Sequelize.literal()` template string with no escape, type cast, or parameter binding. The action ACL is `loggedIn`, so any authenticated account reaches it. The default `auth-basic` authenticator ships `allowSignUp: true`, so the account is obtainable anonymously.
The injection is reachable with the URL paramete
Affected Products
- npm/@nocobase/plugin-notification-in-app-message <= 2.0.60
References
- https://github.com/advisories/GHSA-p849-8hwh-84j9
- https://github.com/nocobase/nocobase/security/advisories/GHSA-p849-8hwh-84j9
- https://nvd.nist.gov/vuln/detail/CVE-2026-52887
- https://github.com/nocobase/nocobase/pull/9630
This critical severity vulnerability with a CVSS score of 10.0 was published on 2026-07-31 via GitHub. Affected: npm/@nocobase/plugin-notification-in-app-message <= 2.0.60.
Risk Timeline
CVE Disclosed2026-07-31 · 3 days ago
Remediation Resources
NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2026-52887Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-53609 | Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operat | CRITICAL | 9.1 |
| CVE-2026-69264 | Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into P | CRITICAL | — |
| CVE-2026-70470 | Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE | CRITICAL | — |
| CVE-2025-4318 | AWS Amplify Studio UI Component Properties Has an Input Validation Issue | CRITICAL | — |
| CVE-2026-11393 | AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Tri | HIGH | 9.0 |
| CVE-2026-54639 | Style Dictionary - Prototype Pollution in convertTokenData utility function | HIGH | 8.8 |
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.