---
id: CVE-2026-53930
title: 'NocoDB: Server-Side Request Forgery via Base Migration URL'
summary: 'NocoDB: Server-Side Request Forgery via Base Migration URL'
severity: medium
cwe:
  - CWE-918
vendor: nocodb
product: nocodb
ecosystem: npm
affected:
  - nocodb <= 0.301.3
published: '2026-06-17'
updated: '2026-06-17'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-h6vv-pcq8-7xm4'
references:
  - url: 'https://github.com/nocodb/nocodb/security/advisories/GHSA-h6vv-pcq8-7xm4'
  - url: 'https://github.com/advisories/GHSA-h6vv-pcq8-7xm4'
tags:
  - ghsa
  - npm
epss: 0.00388
epssPercentile: 0.30163
ingestedAt: '2026-06-29T14:31:47.432Z'
---

## Overview

### Summary
The base-migration endpoint accepted a caller-supplied URL that the migration worker
dereferenced without enforcing protocol or destination, allowing scheme abuse
(`file:`, `ftp:`, etc.) and probing of internal HTTP destinations.

### Details
The `migrate` endpoint is restricted to the workspace owner role by ACL. The remaining
gaps were (a) protocol validation — the controller now parses `body.migrationUrl` as a
`URL` and rejects anything whose protocol is not `http:` or `https:` — and (b) private
destination filtering — the worker already runs through `useAgent(targetUrl)` from
`request-filtering-agent`, which blocks RFC 1918, loopback, and link-local at the
socket layer.

### Impact
With the workspace owner role, a malformed URL could be used to coerce the migration
worker into reading local files or talking to non-HTTP services; combined with the
HTTP-only filter, owner-supplied targets could not reach private ranges.

### Credit
This issue was reported by Devel Group Security Research Team through [@TREXNEGRO](https://github.com/TREXNEGRO).
It was independently reported by [@Lihfdgjr](https://github.com/Lihfdgjr) and [@bugbunny-research (https://github.com/bugbunny-research).

## Affected packages

- `nocodb <= 0.301.3`

## Remediation

Refer to the advisory for the patched release.
