<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 04:16:55 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-338891</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-338891</link>
      <description>EUVD-2026-338891</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-338891</guid>
    </item>
    <item>
      <title>fkie_cve-2026-52887</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-52887</link>
      <description>&lt;p&gt;NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal() template string without escaping or parameter binding, allowing a signed-up authenticated user to run stacked PostgreSQL statements and potentially execute commands with COPY ... TO PROGRAM. This vulnerability is fixed in 2.0.61.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal() template string without escaping or parameter binding, allowing a signed-up authenticated user to run stacked PostgreSQL statements and potentially execute commands with COPY ... TO PROGRAM. This vulnerability is fixed in 2.0.61.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-52887</guid>
    </item>
    <item>
      <title>GHSA-p849-8hwh-84j9 — NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p849-8hwh-84j9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @nocobase/plugin-notification-in-app-message&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`GET /api/myInAppChannels:list` accepts a structured `filter` query parameter. The handler for the `latestMsgReceiveTimestamp` field splices the `$lt` value directly into a `Sequelize.literal()` template string with no escape, type cast, or parameter binding. The action ACL is `loggedIn`, so any authenticated account reaches it. The default `auth-basic` authenticator ships `allowSignUp: true`, so the account is obtainable anonymously.&lt;/p&gt;
&lt;p&gt;The injection is reachable with the URL parameter `filter[latestMsgReceiveTimestamp][$lt]=&amp;lt;expression&amp;gt;`. The `pg` driver in front of Sequelize accepts stacked statements, so the chain extends from boolean and timing oracles to multi-statement payloads.&lt;/p&gt;
&lt;p&gt;The shipped `docker-compose.yml` creates the DB role `nocobase` on a stock `postgres:16` image, which assigns the `rolsuper` attribute by default. `COPY ... TO PROGRAM &amp;#39;...&amp;#39;` therefore runs shell commands as `uid=999(postgres)` inside the database container.&lt;/p&gt;
&lt;p&gt;Result: any anonymous visitor signs up, signs in, and exfiltrates arbitrary rows or executes shell commands inside the database container with one HTTP GET after the sign-in.&lt;/p&gt;
&lt;p&gt;## Affected&lt;/p&gt;
&lt;p&gt;NocoBase server, `@nocobase/plugin-notification-in-app-message` `&amp;lt;=2.0.57`. Confirmed live-exploitable on the official `nocobase/nocobase:2.0.57` Docker image (HEAD `e35a2737d9df139cacecae0151c3326746e2339a`).&lt;/p&gt;
&lt;p&gt;`@nocobase/plugin-notification-in-app-message` is enabled by default in `@nocobase/preset-nocobase`. The default `auth-basic` ships `…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @nocobase/plugin-notification-in-app-message&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`GET /api/myInAppChannels:list` accepts a structured `filter` query parameter. The handler for the `latestMsgReceiveTimestamp` field splices the `$lt` value directly into a `Sequelize.literal()` template string with no escape, type cast, or parameter binding. The action ACL is `loggedIn`, so any authenticated account reaches it. The default `auth-basic` authenticator ships `allowSignUp: true`, so the account is obtainable anonymously.&lt;/p&gt;
&lt;p&gt;The injection is reachable with the URL parameter `filter[latestMsgReceiveTimestamp][$lt]=&amp;lt;expression&amp;gt;`. The `pg` driver in front of Sequelize accepts stacked statements, so the chain extends from boolean and timing oracles to multi-statement payloads.&lt;/p&gt;
&lt;p&gt;The shipped `docker-compose.yml` creates the DB role `nocobase` on a stock `postgres:16` image, which assigns the `rolsuper` attribute by default. `COPY ... TO PROGRAM &amp;#39;...&amp;#39;` therefore runs shell commands as `uid=999(postgres)` inside the database container.&lt;/p&gt;
&lt;p&gt;Result: any anonymous visitor signs up, signs in, and exfiltrates arbitrary rows or executes shell commands inside the database container with one HTTP GET after the sign-in.&lt;/p&gt;
&lt;p&gt;## Affected&lt;/p&gt;
&lt;p&gt;NocoBase server, `@nocobase/plugin-notification-in-app-message` `&amp;lt;=2.0.57`. Confirmed live-exploitable on the official `nocobase/nocobase:2.0.57` Docker image (HEAD `e35a2737d9df139cacecae0151c3326746e2339a`).&lt;/p&gt;
&lt;p&gt;`@nocobase/plugin-notification-in-app-message` is enabled by default in `@nocobase/preset-nocobase`. The default `auth-basic` ships `…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p849-8hwh-84j9</guid>
    </item>
  </channel>
</rss>
