CyberRota
← Ana sayfaya dön

CVE-2026-41640

HIGH · CVSS 7.5 EPSS %4.82 Public Exploit

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-05-07T04:16:28.277 · Çekilme zamanı: 2026-06-06T00:00:35.298039+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

Public Exploit Sinyali

Bu CVE için açıklama veya referanslarda public exploit / PoC / GitHub / Metasploit sinyali tespit edildi.

Not: Bu bağlantılar yalnızca güvenlik araştırması ve doğrulama amacıyla listelenmiştir.

CVE
CVE-2026-41640
Severity
HIGH
CVSS
7.5
EPSS
%4.82

Orijinal NVD Açıklaması

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.39, the queryParentSQL() function in the core database package constructs a recursive CTE query by joining nodeIds with string concatenation instead of using parameterized queries. The nodeIds array contains primary key values read from database rows. An attacker who can create a record with a malicious string primary key can inject arbitrary SQL when any subsequent request triggers recursive eager loading on that collection. This issue has been patched in version 2.0.39.