CRITICAL 10.0 GitHub

CVE-2026-52887

NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

## Summary `GET /api/myInAppChannels:list` accepts a structured `filter` query parameter. The handler for the `latestMsgReceiveTimestamp` field splices the `$lt` value directly into a `Sequelize.literal()` template string with no escape, type cast, or parameter binding. The action ACL is `loggedIn`, so any authenticated account reaches it. The default `auth-basic` authenticator ships `allowSignUp: true`, so the account is obtainable anonymously. The injection is reachable with the URL paramete

Affected Products

References

Published: 2026-07-31 · Source: GitHub · Feed updated: 2026-08-04
This critical severity vulnerability with a CVSS score of 10.0 was published on 2026-07-31 via GitHub. Affected: npm/@nocobase/plugin-notification-in-app-message <= 2.0.60.

Risk Timeline

CVE Disclosed2026-07-31 · 3 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2026-53609Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operatCRITICAL9.1
CVE-2026-69264Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into PCRITICAL
CVE-2026-70470Flowise: Pyodide validator Unicode homoglyph bypass leads to RCECRITICAL
CVE-2025-4318AWS Amplify Studio UI Component Properties Has an Input Validation IssueCRITICAL
CVE-2026-11393AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper TriHIGH9.0
CVE-2026-54639Style Dictionary - Prototype Pollution in convertTokenData utility functionHIGH8.8
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.