THREAT OPS › Threat News › [GHSA] GHSA-p849-8hwh-84j9 (critical) — NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
[GHSA] GHSA-p849-8hwh-84j9 (critical) — NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
GHSA-p849-8hwh-84j9 Severity: critical CVE: CVE-2026-52887
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
## Summary
`GET /api/myInAppChannels:list` accepts a structured `filter` query parameter. The handler for the `latestMsgReceiveTimestamp` field splices the `$lt` value directly into a `Sequelize.literal()` template string with no escape, type cast, or parame
Indicators of compromise
- e35a2737d9df139cacecae0151c3326746e2339asha1
- CVE-2026-52887cve
- http://target:13000/api/auth:signUp?authenticator=basicurl
- http://target:13000/api/auth:signIn?authenticator=basicurl
- http://target:13000/api/myInAppChannels:listurl
- https://turingpoint.deurl
- jan@turingpoint.deemail
Original source: https://github.com/advisories/GHSA-p849-8hwh-84j9