CVE-2026-34825
Severity CVSS v4.0:
HIGH
Type:
CWE-89
SQL Injection
Publication date:
02/04/2026
Last modified:
10/04/2026
Description
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.30, NocoBase plugin-workflow-sql substitutes template variables directly into raw SQL strings via getParsedValue() without parameterization or escaping. Any user who triggers a workflow containing a SQL node with template variables from user-controlled data can inject arbitrary SQL. This issue has been patched in version 2.0.30.
Impact
Base Score 4.0
8.50
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:nocobase:nocobase:*:*:*:*:*:*:*:* | 2.0.30 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



