Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.4
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.37, NocoBase's workflow HTTP request plugin and custom request ...
GHSA-mvvv-v22x-xqwp
CVE-2026-40346
GHSA-mvvv-v22x-xqwp
Summary
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.37, NocoBase's workflow HTTP request plugin and custom request action plugin make server-side HTTP requests to user-provided URLs without any SSRF protection. An auth...
What to do
- Update nocobase plugin-workflow-request to version 2.0.37.
- Update nocobase @nocobase/plugin-workflow-request to version 2.0.37.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | nocobase | plugin-workflow-request |
< 2.0.37 Fix: upgrade to 2.0.37
|
| npm | nocobase | @nocobase/plugin-workflow-request |
< 2.0.37 Fix: upgrade to 2.0.37
|
Original title
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.37, NocoBase's workflow HTTP request plugin and custom request ...
Original description
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.37, NocoBase's workflow HTTP request plugin and custom request action plugin make server-side HTTP requests to user-provided URLs without any SSRF protection. An authenticated user can access internal network services, cloud metadata endpoints, and localhost. Version 2.0.37 contains a patch.
ghsa CVSS4.0
6.4
Vulnerability type
CWE-918
Server-Side Request Forgery (SSRF)
- https://github.com/nocobase/nocobase/security/advisories/GHSA-mvvv-v22x-xqwp
- https://github.com/advisories/GHSA-mvvv-v22x-xqwp
- https://github.com/nocobase/nocobase Product
- https://github.com/nocobase/nocobase/commit/2853368243ed07339c62c548b7d475f4eeaa...
- https://github.com/nocobase/nocobase/pull/9079
- https://github.com/nocobase/nocobase/releases/tag/v2.0.37
Published: 18 Apr 2026 · Updated: 18 Apr 2026 · First seen: 15 Apr 2026