CVE-2026-84701

medium

Description

NocoBase fails to sanitize rich text field values in the read renderer, allowing users with create permissions to store malicious HTML with event handlers. Attackers can write arbitrary markup through the collection API that executes in the browsers of all users viewing the affected record.

References

https://www.vulncheck.com/advisories/nocobase-rich-text-field-stored-cross-site-scripting-via-api

https://github.com/nocobase/nocobase/issues/10416

https://github.com/nocobase/nocobase/blob/v2.2.5/packages/core/client/src/schema-component/antd/input/ReadPretty.tsx

https://github.com/nocobase/nocobase

Details

Source: Mitre, NVD

Published: 2026-09-02

Updated: 2026-09-02

Risk Information

CVSS v2

Base Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 5.4

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Severity: Medium

CVSS v4

Base Score: 5.1

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

Severity: Medium