MEDIUM 6.7 GitHub
CVE-2026-55410
NocoBase backup restore schema name allows command injection
### Summary
NocoBase `@nocobase/plugin-backups` 2.0.57 restores PostgreSQL backups by interpolating the backup metadata schema name into shell command strings that are executed with Node.js `child_process.exec()`. A backup-management user who can restore an uploaded PostgreSQL backup with forced schema restore can place shell metacharacters in `_metadata.json` under `database.schema`, causing arbitrary commands to execute as the NocoBase server process during restore.
The vulnerable plugin is i
Affected Products
- npm/@nocobase/plugin-backups < 2.1.19
References
- https://github.com/advisories/GHSA-p853-83gj-wjj3
- https://github.com/nocobase/nocobase/security/advisories/GHSA-p853-83gj-wjj3
- https://nvd.nist.gov/vuln/detail/CVE-2026-55410
- https://github.com/nocobase/nocobase/commit/0e1aba1b7b112ffc841588963f7343c00edd9806
This medium severity vulnerability with a CVSS score of 6.7 was published on 2026-08-20 via GitHub. Affected: npm/@nocobase/plugin-backups < 2.1.19.
vulnfeed aggregates 11796 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.