NocoDB Stored Cross-Site Scripting Vulnerability in Formula Virtual Cell

Vulnerability

A stored cross-site scripting (XSS) vulnerability has been identified in NocoDB versions prior to 0.301.3. The issue resides in the Formula virtual cell, where results containing 'URI::()' patterns are rendered using 'v-html' without proper sanitization. This oversight allows injected HTML to execute. A user with a Creator role can exploit this by crafting a formula that includes malicious scripts, which are then executed for all viewers of the table.

Impact

Exploitation of this vulnerability could lead to cross-site scripting, allowing for the execution of scripts in the context of the user viewing the table, potentially leading to credential theft.

Remediation

Users can upgrade to NocoDB version 0.301.3 or later to address this vulnerability.

Added: Mar 2, 2026, 5:24 PM
Updated: Mar 2, 2026, 9:17 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
1.7
exploitability
5.0
remediation
7.7
relevance
3.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.