CVE-2026-40346: NocoBase has SSRF in Workflow HTTP Request and Custom Request Plugins
Summary
NocoBase's workflow HTTP request plugin and custom request action plugin make server-side HTTP requests to user-provided URLs without any SSRF protection. An authenticated user can access internal network services, cloud metadata endpoints, and localhost.
Vulnerable Code
1. Workflow HTTP Request Plugin
packages/plugins/@nocobase/plugin-workflow-request/src/server/RequestInstruction.ts lines 117-128: typescript return axios.request({ url: trim(url), // User-controlled, no validation method, headers, params, timeout, ...(method.toLowerCase() !== 'get' && data != null ? { data: transformer ? await transformer(data) : data } : {}), });
The url at line 98 comes directly from user workflow configuration with only whitespace trimming.
2. Custom Request Action Plugin
packages/plugins/@nocobase/plugin-action-custom-request/src/server/actions/send.ts lines 172-198: typescript const axiosRequestConfig = { baseURL: ctx.origin, ...options, url: getParsedValue(url, variables), // User-controlled via template headers: { ... }, params: getParsedValue(arrayToObject(params), variables), data: getParsedValue(toJSON(data), variables), }; const res = await axios(axiosRequestConfig); // No IP validation
Missing Protections
- No request-filtering-agent or SSRF library (confirmed via grep across entire codebase) - No private IP range filtering - No cloud metadata endpoint blocking - No URL scheme validation - No DNS rebinding protection
Attack Scenario
1. Authenticated user creates a workflow with HTTP Request node 2. Sets URL to http://169.254.169.254/latest/meta-data/iam/security-credentials/ 3. Triggers the workflow 4. Server fetches AWS metadata and returns IAM credentials in workflow execution logs
Alternatively via Custom Request action: 1. Create custom request with URL http://127.0.0.1:5432 or http://10.0.0.1:8080/admin 2. Execute the action 3. Server makes request to internal service
Impact
- Cloud metadata theft: AWS/GCP/Azure credentials via metadata endpoints - Internal network access: Scan and interact with services on private IP ranges - Database access: Connect to localhost databases (PostgreSQL, Redis, etc.) - Authentication required: Yes (authenticated user), but any workspace member can create workflows
Other sources
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.37, NocoBase's workflow HTTP request plugin and custom request action plugin make server-side HTTP requests to user-provided URLs without any SSRF protection. An authenticated user can access internal network services, cloud metadata endpoints, and localhost. Version 2.0.37 contains a patch.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40346?
CVE-2026-40346 has a high severity rating due to the potential for Server-Side Request Forgery (SSRF) that can expose internal network services.
How do I fix CVE-2026-40346?
To fix CVE-2026-40346, update the @nocobase/plugin-workflow-request package to version 2.0.37 or later.
Who is affected by CVE-2026-40346?
CVE-2026-40346 affects authenticated users of NocoBase's workflow HTTP request plugin and custom request action plugin.
What type of attack can be executed through CVE-2026-40346?
CVE-2026-40346 can be exploited to execute SSRF attacks, allowing unauthorized access to internal services and cloud metadata.
What are the potential risks of CVE-2026-40346?
The risks of CVE-2026-40346 include unauthorized data exposure and potential compromise of sensitive internal services.