🚨 CVE-2026-84701
NocoBase fails to sanitize rich text field values in the read renderer, allowing users with create permissions to store malicious HTML with event handlers. Attackers can write arbitrary markup through the collection API that executes in the browsers of all users viewing the affected record.
🎖@cveNotify

GitHub
GitHub - nocobase/nocobase: NocoBase is an open-source AI + no-code platform for building business systems fast. Instead of generating…
NocoBase is an open-source AI + no-code platform for building business systems fast. Instead of generating everything from scratch, AI works on top of production-proven infrastructure and a WYSIWYG...
September 2, 2026 26