Security Wins

Real security victories in public repositories powered by Kolega.dev. See how our AI-powered platform identifies vulnerabilities and delivers verified fixes to strengthen open source projects.

December 2025
15 min read
Faizan Raza
NocoDB Security Assessment
NocoDB
NocoDBSQL InjectionSSRFAuthentication Bypass
Identified 5 security vulnerabilities including 1 critical SQL injection in Oracle client, 2 high-severity SSRF issues in attachment uploads, WebSocket authentication bypass, and information disclosure. Delivered comprehensive fixes with tested pull requests, fixes have been implemented by NocoDB on their own internal private branches.

Simple 3 click setup.

Deploy Kolega.dev.

Find and fix your technical debt.