Impact
NocoBase versions up to and including 2.1.20 contain a CWE‑918 Server‑Side Request Forgery vulnerability that permits any authenticated administrator to issue arbitrary outbound HTTP requests through the serverRequest wrapper. By supplying malicious URLs in workflow nodes, custom request action buttons, or the AI plugin, an attacker can direct traffic to loopback interfaces, RFC‑1918 private enabling internal network port enumeration, host discovery, and the extraction of IAM role credentials a foothold for further escalation.
Affected Systems
The affected vendor is nocobase and the product is NocoBase. All releases through 2.1.20 are vulnerable; the CVE data does not specify that the flaw is resolved in later versions. No explicit version ranges beyond these releases are listed in the CNA data.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, while the EPSS score of < 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers must possess authenticated administrator privileges and use the built‑in serverRequest wrapper; once authorized, the risk is moderate due to potential internal data exposure, but the likelihood of exploitation remains very low.
OpenCVE Enrichment