Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
NocoBase Notification component allows remote attackers to manipulate the `latestMsgReceiveTimestamp` argument and trigger SQL injection via `Sequelize.literal` in the `/api/myInAppChannels` endpoint.
An unauthenticated attacker over the network can execute arbitrary SQL queries against the database by injecting malicious payloads through the `latestMsgReceiveTimestamp` parameter, potentially allowing them to read, modify, or delete database contents.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Not specified in provided data
Upgrade NocoBase to a version newer than 2.0.60. Implement input validation and parameterized queries to prevent SQL injection. Apply web application firewall rules to detect and block SQL injection attempts targeting the `/api/myInAppChannels` endpoint. Consider restricting access to the notification API endpoint if not widely required by end users.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
NVD published the first details for CVE-2026-52887
Feedly found the first article mentioning CVE-2026-52887 . See article
A CVSS base score of 10 has been assigned.
CVE-2026-52887 - Exploits & Severity - Feedly
CVE-2026-52887 NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notificati…
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
