<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 13:33:23 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-329810</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329810</link>
      <description>EUVD-2026-329810</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329810</guid>
    </item>
    <item>
      <title>fkie_cve-2026-46549</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46549</link>
      <description>&lt;p&gt;NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the OAuth token strategy attached oauth_scope and oauth_granted_resources to the request user, but the ACL middleware never consulted either. An OAuth token issued with a restricted scope (e.g. MCP-only) therefore inherited the full permissions of the underlying user across all routes; the granted_resources.base_id restriction was bypassed on org-level endpoints that don&amp;#39;t populate req.context.base_id. This vulnerability is fixed in 2026.04.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the OAuth token strategy attached oauth_scope and oauth_granted_resources to the request user, but the ACL middleware never consulted either. An OAuth token issued with a restricted scope (e.g. MCP-only) therefore inherited the full permissions of the underlying user across all routes; the granted_resources.base_id restriction was bypassed on org-level endpoints that don&amp;#39;t populate req.context.base_id. This vulnerability is fixed in 2026.04.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-46549</guid>
    </item>
    <item>
      <title>GHSA-m5qg-rvjq-727p — NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m5qg-rvjq-727p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nocodb&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The OAuth token strategy attached `oauth_scope` and `oauth_granted_resources` to the request user, but the ACL middleware never consulted either. An OAuth token issued with a restricted scope (e.g. MCP-only) therefore inherited the full permissions of the underlying user across all routes; the `granted_resources.base_id` restriction was bypassed on org-level endpoints that don&amp;#39;t populate `req.context.base_id`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;In `packages/nocodb/src/strategies/oauth-token.strategy.ts`, the strategy set `is_oauth_token`, `oauth_client_id`, `oauth_granted_resources`, and `oauth_scope` on the user object, then mapped through to the user&amp;#39;s existing `roles` / `base_roles`. The ACL middleware in `extract-ids.middleware.ts` honoured `is_api_token` via `blockApiTokenAccess` but had no equivalent gate for `is_oauth_token` or scope-string enforcement.&lt;/p&gt;
&lt;p&gt;The base/workspace restriction logic short-circuited when `req.context.base_id` was unset (org-level routes), so an OAuth token scoped to one base could still call org-level endpoints as the underlying user.&lt;/p&gt;
&lt;p&gt;The fix adds a path-prefix allowlist (`[&amp;#39;/mcp&amp;#39;, &amp;#39;/api/v3/&amp;#39;, &amp;#39;/auth/user/me&amp;#39;]`) enforced inside the strategy and a `blockOAuthTokenAccess` ACL flag for endpoints that should never accept OAuth tokens.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;- Scope escalation: tokens issued with a narrow scope received the underlying user&amp;#39;s full role.
- Resource boundary bypass: per-base restrictions did not apply to org-level routes.
- Violates least-privilege exp…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nocodb&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The OAuth token strategy attached `oauth_scope` and `oauth_granted_resources` to the request user, but the ACL middleware never consulted either. An OAuth token issued with a restricted scope (e.g. MCP-only) therefore inherited the full permissions of the underlying user across all routes; the `granted_resources.base_id` restriction was bypassed on org-level endpoints that don&amp;#39;t populate `req.context.base_id`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;In `packages/nocodb/src/strategies/oauth-token.strategy.ts`, the strategy set `is_oauth_token`, `oauth_client_id`, `oauth_granted_resources`, and `oauth_scope` on the user object, then mapped through to the user&amp;#39;s existing `roles` / `base_roles`. The ACL middleware in `extract-ids.middleware.ts` honoured `is_api_token` via `blockApiTokenAccess` but had no equivalent gate for `is_oauth_token` or scope-string enforcement.&lt;/p&gt;
&lt;p&gt;The base/workspace restriction logic short-circuited when `req.context.base_id` was unset (org-level routes), so an OAuth token scoped to one base could still call org-level endpoints as the underlying user.&lt;/p&gt;
&lt;p&gt;The fix adds a path-prefix allowlist (`[&amp;#39;/mcp&amp;#39;, &amp;#39;/api/v3/&amp;#39;, &amp;#39;/auth/user/me&amp;#39;]`) enforced inside the strategy and a `blockOAuthTokenAccess` ACL flag for endpoints that should never accept OAuth tokens.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;- Scope escalation: tokens issued with a narrow scope received the underlying user&amp;#39;s full role.
- Resource boundary bypass: per-base restrictions did not apply to org-level routes.
- Violates least-privilege exp…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m5qg-rvjq-727p</guid>
    </item>
  </channel>
</rss>
