{"id":"GHSA-gprh-27j3-g5h4","summary":"NocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL","details":"### Summary\nThe spreadsheet-fetch endpoint (`axiosRequestMake`) accepted URLs whose path\ncontained a permitted extension anywhere in the string, and applied a hand-rolled\nregex blocklist that omitted `127.0.0.0/8` and `169.254.0.0/16`, allowing the\ncloud-metadata endpoint to be reached with a crafted URL.\n\n### Details\nThe extension matcher is now anchored to the end of the path or immediately before\nthe query string (`/\\.(xls|xlsx|xlsm|ods|ots)(\\?|$)/i` and `/\\.(csv)(\\?|$)/i`), so\n`http://169.254.169.254/credentials/.xlsx` no longer satisfies the format gate. The\nhand-rolled IP blocklist is removed in favour of `useAgent(url)` from\n`request-filtering-agent`, which blocks private and loopback ranges at the socket\nlayer.\n\n### Impact\nAuthenticated users with editor permission could read cloud metadata and other\ninternal HTTP endpoints reachable from the NocoDB process. On affected installs the\nspreadsheet import path was a credential-exfiltration primitive on cloud hosts.\n\n### Credit\nThis issue was reported by Devel Group Security Research Team through [@TREXNEGRO](https://github.com/TREXNEGRO).\nIt was independently reported by [@l3tchupkt](https://github.com/l3tchupkt).","aliases":["CVE-2026-53927"],"modified":"2026-07-20T21:30:35.483561572Z","published":"2026-06-17T14:06:43Z","database_specific":{"cwe_ids":["CWE-918"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-06-17T14:06:43Z","nvd_published_at":"2026-06-23T21:17:01Z"},"references":[{"type":"WEB","url":"https://github.com/nocodb/nocodb/security/advisories/GHSA-gprh-27j3-g5h4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53927"},{"type":"PACKAGE","url":"https://github.com/nocodb/nocodb"}],"affected":[{"package":{"name":"nocodb","ecosystem":"npm","purl":"pkg:npm/nocodb"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.301.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-gprh-27j3-g5h4/GHSA-gprh-27j3-g5h4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}