---
id: CVE-2026-53929
title: 'NocoDB: Stored Cross-Site Scripting via Secure Attachment'
summary: 'NocoDB: Stored Cross-Site Scripting via Secure Attachment'
severity: medium
cwe:
  - CWE-79
vendor: nocodb
product: nocodb
ecosystem: npm
affected:
  - nocodb <= 0.301.3
published: '2026-06-17'
updated: '2026-06-17'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-6mhr-74x2-98v9'
references:
  - url: 'https://github.com/nocodb/nocodb/security/advisories/GHSA-6mhr-74x2-98v9'
  - url: 'https://github.com/advisories/GHSA-6mhr-74x2-98v9'
tags:
  - ghsa
  - npm
epss: 0.00396
epssPercentile: 0.31102
ingestedAt: '2026-06-29T14:31:47.433Z'
---

## Overview

### Summary
With `NC_SECURE_ATTACHMENTS=true`, an authenticated uploader could deliver `.html` or
`.svg` attachments that the browser rendered inline from the NocoDB origin instead of
forcing a download.

### Details
The signed attachment handler stored response-header overrides under PascalCase keys
(`ResponseContentDisposition`, `ResponseContentType`) while the controller that served
the file read them under lowercase-hyphen names (`response-content-disposition`). The
mismatch dropped the `Content-Disposition: attachment` header, leaving Express to
auto-render `.html`, `.svg`, and similar inline. The fix corrects the key case and
additionally forces `Content-Disposition: attachment` and
`Content-Type: application/octet-stream` for any MIME type not on the preview
allowlist.

### Impact
Stored Cross-Site Scripting in the NocoDB origin from inline-rendered uploads. Script
executing in the victim's browser can read the auth JWT from `localStorage`.
Exploitation requires authenticated upload permission and the secure-attachment mode
to be enabled.

### Credit
This issue was reported by [@bugbunny-research](https://github.com/bugbunny-research).
It was independently reported by [@DavidCarliez](https://github.com/DavidCarliez).

## Affected packages

- `nocodb <= 0.301.3`

## Remediation

Refer to the advisory for the patched release.
