{"id":"GHSA-rvp5-9p55-f5rp","summary":"NocoDB: Open Redirect via Hash Fragment in hashRedirect Plugin","details":"### Summary\n\nThe client-side `hashRedirect` plugin called `window.location.replace()` on a path extracted from the URL hash fragment after only checking `hashPath.startsWith('/')`. Protocol-relative URLs (`//attacker.com/…`) also satisfy that check, so a crafted link such as `https://nocodb.example/#//attacker.com/phishing` silently redirected visitors to an attacker-controlled origin.\n\n### Details\n\nIn `packages/nc-gui/plugins/hashRedirect.client.ts`, the plugin extracted the hash content and normalised it into `cleanUrl`:\n\n```ts\nlet cleanUrl = hashPath.startsWith('/') ? hashPath : `/${hashPath}`\nif (hashQuery) cleanUrl += `?${hashQuery}`\nwindow.location.replace(cleanUrl)\n```\n\n`startsWith('/')` returns true for `//attacker.com/...`, which browsers interpret as a protocol-relative absolute URL. No hostname check was performed before the redirect. The fix adds an early `if (/^\\/[/\\\\]/.test(hashPath)) return` to reject protocol-relative paths.\n\n### Impact\n\n- Open redirect from any NocoDB origin to an attacker-controlled domain.\n- No authentication required; the attack lands the victim on an attacker-controlled page that may impersonate a NocoDB login.\n\n### Credit\n\nThis issue was reported by [@fg0x0](https://github.com/fg0x0).","aliases":["CVE-2026-47377"],"modified":"2026-07-20T21:30:42.868426509Z","published":"2026-06-05T16:00:15Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-06-05T16:00:15Z","nvd_published_at":"2026-06-23T21:16:59Z","cwe_ids":["CWE-601"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/nocodb/nocodb/security/advisories/GHSA-rvp5-9p55-f5rp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47377"},{"type":"PACKAGE","url":"https://github.com/nocodb/nocodb"},{"type":"WEB","url":"https://github.com/nocodb/nocodb/releases/tag/2026.04.1"}],"affected":[{"package":{"name":"nocodb","ecosystem":"npm","purl":"pkg:npm/nocodb"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2026.04.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-rvp5-9p55-f5rp/GHSA-rvp5-9p55-f5rp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}