<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T09:30:21.959236+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329859</id>
    <title>EUVD-2026-329859</title>
    <updated>2026-10-06T09:30:22.009226+00:00</updated>
    <content>EUVD-2026-329859</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329859"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46552</id>
    <title>fkie_cve-2026-46552</title>
    <updated>2026-10-06T09:30:22.009268+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, shared-base sessions were granted the same base-member capabilities as authenticated viewers. Using only the shared-base UUID (xc-shared-base-id), an attacker could enumerate base members and invite an arbitrary email into the base as a real member. The invited user could then redeem the invite via the normal signup flow and retain authenticated access even after the owner revoked the shared link. Shared-base sessions were mapped to ProjectRoles.VIEWER in packages/nocodb/src/strategies/base-view.strategy/base-view.strategy.ts, and packages/nocodb/src/utils/acl.ts granted baseUserList and userInvite to that role. The shared frontend (packages/nc-gui/composables/useApi/interceptors.ts) deliberately removed auth headers in favour of the shared-base header, but the ACL middleware did not distinguish shared sessions from genuine viewers. This vulnerability is fixed in 2026.04.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-46552"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-chqv-vrj7-qffp</id>
    <title>GHSA-chqv-vrj7-qffp — NocoDB: Shared-base link access can invite arbitrary users as persistent base members</title>
    <updated>2026-10-06T09:30:22.009306+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: nocodb</p>
<p>### Summary</p>
<p>Shared-base sessions were granted the same base-member capabilities as authenticated viewers. Using only the shared-base UUID (`xc-shared-base-id`), an attacker could enumerate base members and invite an arbitrary email into the base as a real member. The invited user could then redeem the invite via the normal signup flow and retain authenticated access even after the owner revoked the shared link.</p>
<p>### Details</p>
<p>Shared-base sessions were mapped to `ProjectRoles.VIEWER` in `packages/nocodb/src/strategies/base-view.strategy/base-view.strategy.ts`, and `packages/nocodb/src/utils/acl.ts` granted `baseUserList` and `userInvite` to that role. The shared frontend (`packages/nc-gui/composables/useApi/interceptors.ts`) deliberately removed auth headers in favour of the shared-base header, but the ACL middleware did not distinguish shared sessions from genuine viewers.</p>
<p>The end-to-end chain:</p>
<p>- `GET /api/v2/meta/bases/:baseId/users` returned the member list to shared-base callers (`@Acl('baseUserList')`).
- `POST /api/v2/meta/bases/:baseId/users` accepted an invite from shared-base callers (`@Acl('userInvite')`); `base-users.service.ts` inserted a real `nc_users_v2` row with `invite_token` and a `nc_base_users_v2` row for the target base, with `invited_by = null`.
- The invited account redeemed the invite through the normal signup path (`users.service.ts`), gaining a persistent JWT scoped to the base.
- Revoking the shared link did not affect the redeemed account.</p>
<p>### I…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-chqv-vrj7-qffp"/>
  </entry>
</feed>
