Vulnerability record · CVE-2022-22121 · published 10 January 2022
CVE-2022-22121: Nocodb csv injection vulnerability
Nocodb · Nocodb
In NocoDB, versions 0.81.0 through 0.83.8 are affected by CSV Injection vulnerability (Formula Injection). A low privileged attacker can create a new table to inject payloads in the table rows. When an administrator accesses the User Management endpoint and exports the data as a CSV file and opens it, the payload gets executed.
Description
In NocoDB, versions 0.81.0 through 0.83.8 are affected by CSV Injection vulnerability (Formula Injection). A low privileged attacker can create a new table to inject payloads in the table rows. When an administrator accesses the User Management endpoint and exports the data as a CSV file and opens it, the payload gets executed.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/nocodb/nocodb/commit/079e3abe | PatchThird Party Advisory |
| https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-22121 | ExploitThird Party Advisory |
| https://github.com/nocodb/nocodb/commit/079e3abe | PatchThird Party Advisory |
| https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-22121 | ExploitThird Party Advisory |
Track CVE-2022-22121 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-22121), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.