NocoBase — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
July 16, 2026
Last Seen
August 18, 2026

Related Threat Clusters

Recent Intelligence Reports

  • Hacking your life with AI can get you hacked: How AI orchestration platforms ship RCE by design — Reddit · August 18, 2026
  • Hacking your life with AI can get you hacked — Endorlabs · August 18, 2026
  • CVE-2026-52887 AKAOMA CVE VULNERABILITIES / 12h NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal() template string without escaping or parameter binding, allowing a signed-up authenticated user to run stacked PostgreSQL statements an — cve.akaoma.com · July 16, 2026
  • CVE-2026-52887 - Exploits & Severity — Feedly · July 16, 2026

CVSS v3.1 Breakdown