NocoBase fails to sanitize rich text field values in the read renderer, allowing users with create permissions to store malicious HTML with event handlers. Attackers can write arbitrary markup through the collection API that executes in the browsers of all users viewing the affected record.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 02 Sep 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NocoBase fails to sanitize rich text field values in the read renderer, allowing users with create permissions to store malicious HTML with event handlers. Attackers can write arbitrary markup through the collection API that executes in the browsers of all users viewing the affected record. | |
| Title | NocoBase Rich Text Field Stored Cross-Site Scripting via API | |
| First Time appeared |
Nocobase
Nocobase nocobase |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:nocobase:nocobase:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nocobase
Nocobase nocobase |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-02T00:37:55.776Z
Reserved: 2026-09-01T23:24:29.734Z
Link: CVE-2026-84701
No data.
Status : Received
Published: 2026-09-02T01:17:25.287
Modified: 2026-09-02T01:17:25.287
Link: CVE-2026-84701
No data.
OpenCVE Enrichment
Updated: 2026-09-02T04:30:04Z
Weaknesses