A vulnerability was found in NocoDB up to 2026.05.0. It has been rated as critical. The impacted element is an unknown function of the file noco.db. The manipulation leads to path traversal.

This vulnerability is referenced as CVE-2026-47385. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is advised.