CVE-2026-47377EPSS p15.0%
CVE-2026-47377CVE-2026-47377
Description
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the client-side hashRedirect plugin called window.location.replace() on a path extracted from the URL hash fragment after only checking hashPath.startsWith('/'). Protocol-relative URLs (//attacker.com/…) also satisfy that check, so a crafted link silently redirected visitors to an attacker-controlled origin. This vulnerability is fixed in 2026.04.1.
Scoring
| EPSS | 0.24% probability of exploitation · percentile 15.0% · 2026-08-08T12:02:54Z |
| Last modified | 2026-06-25 |