Impact
NocoBase versions up to and including 2.1.20 contain a CWE‑918 Server‑Side Request Forgery vulnerability that permits any authenticated administrator to issue arbitrary outbound HTTP requests through the serverRequest wrapper. By supplying malicious URLs in workflow nodes, custom request action buttons, or the AI plugin, an attacker can direct traffic to loopback interfaces, RFC‑1918 private ranges, and cloud instance metadata endpoints. This enables internal network port enumeration, host discovery, and the extraction of IAM role credentials from metadata services, thereby compromising internal confidentiality and potentially providing a foothold for further escalation.
Affected Systems
The affected vendor is nocobase and the product is NocoBase. All releases through 2.1.20 are vulnerable; the CVE data does not specify that the flaw is resolved in later versions. No explicit version ranges beyond these releases are listed in the CNA data.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, while the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers must possess authenticated administrator privileges and use the built‑in serverRequest wrapper; once authorized, they can target internal services and harvest credentials. Overall, the risk is moderate due to potential internal data exposure, but the likelihood of exploitation remains very low.
OpenCVE Enrichment