VDB
Sign up
MEDIUM

GHSA-wwp2-x4rj-j8rm

NocoDB Vulnerable to Stored Cross-Site Scripting via Rich Text Cells

Quick fix

GHSA-wwp2-x4rj-j8rm — nocodb: upgrade to the fixed version with the command below.

npm install nocodb@0.301.3

Details

### Summary Rich text cell content rendered via `v-html` without sanitization, enabling stored XSS.

### Details Rich text in `TextArea.vue` was parsed by markdown-it with `html: true` and injected via `v-html` without DOMPurify. A user with Editor role can inject arbitrary HTML that executes for all viewers.

### Impact Stored XSS — malicious scripts execute for any user viewing the cell.

### Credit This issue was discovered by an AI agent developed by the GitHub Security Lab and reviewed by GHSL team members [@p-](https://github.com/p-) (Peter Stockli) and [@m-y-mo](https://github.com/m-y-mo) (Man Yue Mo).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/nocodb
Introduced in: 0Fixed in: 0.301.3
Fixnpm install nocodb@0.301.3

References