{"id":"GHSA-4w6r-5c2j-qf5f","summary":"NocoDB: Hidden Column Exposure in Public Shared View Endpoints","details":"### Summary\nPublic shared-view endpoints exposed values from columns that the view owner had\nhidden, via three independent paths: groupBy returned raw values for any column\nnamed in the request, filter and sort arrays operated on hidden columns enabling\nboolean-blind extraction, and the related-data list accepted arbitrary link-column\nIDs from other tables in the same base.\n\n### Details\nA new `sanitizeListArgsForPublicView` helper now strips request keys that should\nnever be caller-controlled (e.g. `getHiddenColumn`, `nested`), parses `where`\nclauses against a restricted alias map that only contains visible columns, and\nrecursively removes filter/sort entries whose `fk_column_id` is not in the visible\nset. `validateGroupByColumnNames` and `validateGroupColumnId` reject groupBy\nrequests whose `column_name` (CSV-style) or `groupColumnId` is not in the visible\nor group-by column set. `relDataList` now checks `column.fk_model_id ===\ncurrentModel.id` before resolving the linked table, matching the pre-existing\ncheck on `publicMmList` and `publicHmList`.\n\n### Impact\nAnyone with a shared-view UUID could enumerate hidden-column values directly (via\ngroupBy), confirm hidden-column values by observing row counts (via filter), or\nread records from unrelated tables in the same base (via the related-data list).\nNo authentication was required.\n\n### Credit\nThis issue was reported by [@0xBassia](https://github.com/0xBassia).\nIt was independently reported by [@b-hermes](https://github.com/b-hermes).","aliases":["CVE-2026-47378"],"modified":"2026-07-20T21:30:31.661606045Z","published":"2026-06-05T16:03:11Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-06-05T16:03:11Z","nvd_published_at":"2026-06-23T21:16:59Z","cwe_ids":["CWE-639"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/nocodb/nocodb/security/advisories/GHSA-4w6r-5c2j-qf5f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47378"},{"type":"PACKAGE","url":"https://github.com/nocodb/nocodb"},{"type":"WEB","url":"https://github.com/nocodb/nocodb/releases/tag/2026.04.1"}],"affected":[{"package":{"name":"nocodb","ecosystem":"npm","purl":"pkg:npm/nocodb"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2026.04.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-4w6r-5c2j-qf5f/GHSA-4w6r-5c2j-qf5f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}