MEDIUM6.5
GHSA-grv6-m753-3w2g
NocoDB vulnerable to Denial of Service
Quick fix
GHSA-grv6-m753-3w2g — nocodb: upgrade to the fixed version with the command below.
npm install nocodb@0.92.0Details
NocoDB prior to 0.92.0 allows actors to insert large characters into the input field `New Project` on the create field, which can cause a Denial of Service (DoS) via a crafted HTTP request. Version 0.92.0 fixes this issue.
Are you affected?
Enter the version of the package you're using.