CVE-2026-34825 | nocobase NocoBase Plugin up to 2.0.29 Parameter getParsedValue sql injection (GHSA-vx58-fwwq-5g8j)
A vulnerability, which was classified as critical, was found in nocobase NocoBase Plugin up to 2.0.29. This vulnerability affects the function getParsedValue of the component Parameter Handler. Such manipulation leads to sql injection.
This vulnerability is listed as CVE-2026-34825. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.