---
id: CVE-2026-53928
title: 'NocoDB: Refresh Tokens Persist Through Password Recovery'
summary: 'NocoDB: Refresh Tokens Persist Through Password Recovery'
severity: medium
cwe:
  - CWE-613
vendor: nocodb
product: nocodb
ecosystem: npm
affected:
  - nocodb <= 0.301.3
published: '2026-06-17'
updated: '2026-06-17'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-r989-7g3j-wjhw'
references:
  - url: 'https://github.com/nocodb/nocodb/security/advisories/GHSA-r989-7g3j-wjhw'
  - url: 'https://github.com/advisories/GHSA-r989-7g3j-wjhw'
tags:
  - ghsa
  - npm
epss: 0.00314
epssPercentile: 0.21667
ingestedAt: '2026-06-29T14:31:47.435Z'
---

## Overview

### Summary
A stolen refresh token survived a password-forgot flow and could be used to mint fresh
JWTs even after the user reset their password.

### Details
`passwordChange` and `passwordReset` deleted the user's refresh tokens, but
`passwordForgot` only rotated `token_version` and revoked OAuth tokens — it did not
call `UserRefreshToken.deleteAllUserToken(user.id)`. An attacker holding a captured
refresh cookie could still exchange it for a new access token after the victim
triggered the recovery flow.

### Impact
Persistent unauthorized access after password recovery. Once a refresh token leaks, the
documented "Forgot password" recovery flow did not in fact revoke the attacker's
session.

### Credit
This issue was reported by [@bugbunny-research](https://github.com/bugbunny-research).

## Affected packages

- `nocodb <= 0.301.3`

## Remediation

Refer to the advisory for the patched release.
