{"id":"GHSA-cxv7-gmmp-228p","summary":"NocoDB: Postgres SQL Injection in Formula `ARRAYSORT`","details":"### Summary\n\nAn authenticated user with `columnAdd` permission on a Postgres-backed base can inject arbitrary SQL into the formula engine via the optional `direction` argument of `ARRAYSORT(...)`. The value is unrestricted by formula validation and embedded into a `knex.raw` `ORDER BY` clause, executing during column creation and on every subsequent record read of the formula column.\n\n### Details\n\nThe vulnerability is specific to the Postgres mapping for `ARRAYSORT` in `packages/nocodb/src/db/functionMappings/pg.ts`. Two factors combine:\n\n1. `ARRAYSORT` declares only argument count, not `validation.args.type`, so `validate-extract-tree.ts` does not enforce an allowlist on the second argument.\n2. The Postgres mapping then passes the attacker-controlled value through `sanitize(knex.raw(...))` into a raw SQL fragment:\n\n```ts\nconst direction = pt.arguments[1]\n  ? sanitize(\n      knex.raw(pt.arguments[1]?.value ?? (await fn(pt.arguments[1])).builder),\n    )\n  : knex.raw('asc');\n\nreturn {\n  builder: knex.raw(`ARRAY(SELECT UNNEST(??) ORDER BY 1 ??)`, [source, direction]),\n};\n```\n\n`sanitize()` in `sqlSanitize.ts` only escapes `?` placeholder characters; it does not validate SQL syntax. A payload such as `\"desc, (SELECT COUNT(*) FROM generate_series(1,30000000))\"` is accepted, persisted, and re-executed on every read of the formula column.\n\n### Impact\n\n- Authenticated SQL injection against Postgres-backed bases.\n- Requires `columnAdd` permission (creator/owner-level).\n- Proven impact: attacker-controlled heavy SQL causing multi-second query stalls (DoS).\n- Potentially extendable to broader SQL injection outcomes depending on database permissions and deployment hardening.\n- Limited to Postgres backends.\n\n### Credit\n\nThis issue was reported by [@leduckhuong](https://github.com/leduckhuong).","aliases":["CVE-2026-47375"],"modified":"2026-07-20T21:30:34.498307019Z","published":"2026-06-05T15:59:28Z","database_specific":{"nvd_published_at":"2026-06-23T21:16:59Z","cwe_ids":["CWE-89"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-06-05T15:59:28Z"},"references":[{"type":"WEB","url":"https://github.com/nocodb/nocodb/security/advisories/GHSA-cxv7-gmmp-228p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47375"},{"type":"PACKAGE","url":"https://github.com/nocodb/nocodb"},{"type":"WEB","url":"https://github.com/nocodb/nocodb/releases/tag/2026.04.1"}],"affected":[{"package":{"name":"nocodb","ecosystem":"npm","purl":"pkg:npm/nocodb"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2026.04.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-cxv7-gmmp-228p/GHSA-cxv7-gmmp-228p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H"}]}