{"id":"GHSA-8m7c-hf24-5g47","summary":"NocoDB: OAuth Authorization Code Race Condition","details":"### Summary\nTwo concurrent token-exchange requests using the same OAuth authorization code could\neach mint a distinct valid `(access_token, refresh_token)` pair, breaking the\nsingle-use guarantee that PKCE relies on.\n\n### Details\nThe token-exchange flow read `is_used` and called `markAsUsed` as an unconditional\nupdate at the end of the path. A new `OAuthAuthorizationCode.claimByCode` method now\nperforms an atomic compare-and-swap (`WHERE code = ? AND is_used = false`) and is\ncalled immediately before `OAuthToken.insert`, after redirect-URI, PKCE, and client\nauthentication have all succeeded. Only the first concurrent caller's `UPDATE` wins;\nthe rest see `invalid_grant: Authorization code has already been used`.\n\n### Impact\nAn attacker who has observed an authorization code and the corresponding PKCE\nverifier (for example through a malicious OAuth-aware client or by racing a real\nexchange) could obtain a long-lived refresh token in addition to the legitimate one.\n\n### Credit\nThis issue was reported by [@eddieran](https://github.com/eddieran).","aliases":["CVE-2026-47386"],"modified":"2026-07-20T21:30:33.424786522Z","published":"2026-06-05T16:20:32Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-06-05T16:20:32Z","nvd_published_at":"2026-06-23T21:17:00Z","cwe_ids":["CWE-362"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/nocodb/nocodb/security/advisories/GHSA-8m7c-hf24-5g47"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47386"},{"type":"PACKAGE","url":"https://github.com/nocodb/nocodb"},{"type":"WEB","url":"https://github.com/nocodb/nocodb/releases/tag/2026.05.1"}],"affected":[{"package":{"name":"nocodb","ecosystem":"npm","purl":"pkg:npm/nocodb"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2026.05.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-8m7c-hf24-5g47/GHSA-8m7c-hf24-5g47.json","last_known_affected_version_range":"\u003c= 2026.05.0"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}