THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-p849-8hwh-84j9 (critical) — NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

[GHSA] GHSA-p849-8hwh-84j9 (critical) — NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

highgithub_advisoriesPublished 2026-07-31

GHSA-p849-8hwh-84j9 Severity: critical CVE: CVE-2026-52887

NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

## Summary

`GET /api/myInAppChannels:list` accepts a structured `filter` query parameter. The handler for the `latestMsgReceiveTimestamp` field splices the `$lt` value directly into a `Sequelize.literal()` template string with no escape, type cast, or parame

Indicators of compromise

Original source: https://github.com/advisories/GHSA-p849-8hwh-84j9