{"id":"GHSA-h6vv-pcq8-7xm4","summary":"NocoDB: Server-Side Request Forgery via Base Migration URL","details":"### Summary\nThe base-migration endpoint accepted a caller-supplied URL that the migration worker\ndereferenced without enforcing protocol or destination, allowing scheme abuse\n(`file:`, `ftp:`, etc.) and probing of internal HTTP destinations.\n\n### Details\nThe `migrate` endpoint is restricted to the workspace owner role by ACL. The remaining\ngaps were (a) protocol validation — the controller now parses `body.migrationUrl` as a\n`URL` and rejects anything whose protocol is not `http:` or `https:` — and (b) private\ndestination filtering — the worker already runs through `useAgent(targetUrl)` from\n`request-filtering-agent`, which blocks RFC 1918, loopback, and link-local at the\nsocket layer.\n\n### Impact\nWith the workspace owner role, a malformed URL could be used to coerce the migration\nworker into reading local files or talking to non-HTTP services; combined with the\nHTTP-only filter, owner-supplied targets could not reach private ranges.\n\n### Credit\nThis issue was reported by Devel Group Security Research Team through [@TREXNEGRO](https://github.com/TREXNEGRO).\nIt was independently reported by [@Lihfdgjr](https://github.com/Lihfdgjr) and [@bugbunny-research (https://github.com/bugbunny-research).","aliases":["CVE-2026-53930"],"modified":"2026-07-20T21:30:35.483373699Z","published":"2026-06-17T14:08:04Z","database_specific":{"nvd_published_at":"2026-06-23T21:17:01Z","cwe_ids":["CWE-918"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-06-17T14:08:04Z"},"references":[{"type":"WEB","url":"https://github.com/nocodb/nocodb/security/advisories/GHSA-h6vv-pcq8-7xm4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53930"},{"type":"PACKAGE","url":"https://github.com/nocodb/nocodb"}],"affected":[{"package":{"name":"nocodb","ecosystem":"npm","purl":"pkg:npm/nocodb"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.301.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-h6vv-pcq8-7xm4/GHSA-h6vv-pcq8-7xm4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}