CVE-2026-46551: Nocodb Arraysort Ast Sqli
An unvalidated AST node value (`.value`) is passed directly into a raw SQL query binding (`knex.raw()`). In NocoDB formula resolution, passing a literal string this way without parameterization or strict allowlisting (such as for 'ASC' or 'DESC') allows an attacker to bypass basic sanitization and execute arbitrary SQL injection via the ORDER BY clause. Ensu
greprules fetch cve-2026-46551-nocodb-arraysort-ast-sqli --engine opengrepDescription
An unvalidated AST node value (`.value`) is passed directly into a raw SQL query binding (`knex.raw()`). In NocoDB formula resolution, passing a literal string this way without parameterization or strict allowlisting (such as for 'ASC' or 'DESC') allows an attacker to bypass basic sanitization and execute arbitrary SQL injection via the ORDER BY clause. Ensu
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.