CVE-2023-35843 is a path traversal vulnerability in NocoDB versions through 0.106.0 (or 0.109.1) that allows unauthenticated attackers to read arbitrary files on the server by manipulating the /download route. This high-severity vulnerability (CVSS 7.5) has a low attack complexity and could lead to the compromise of sensitive data like configuration files and source code. While not currently in CISA's KEV catalog, public Nuclei templates exist for exploitation, and its high EPSS score indicates a significant likelihood of future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.106.1CPE matchmatch criteria | cpe:2.3:a:nocodb:nocodb:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.