NodeBB Patches Eight High-Severity Flaws Enabling XSS, Admin Bypass, and Data Theft
ID: 26cdd265-8dea-5f67-9531-b330ad1e0402
STIX ID: report--26cdd265-8dea-5f67-9531-b330ad1e0402
Feed Name: Cyber Press
NodeBB disclosed eight high-severity vulnerabilities affecting default instances prior to 4.14.0 discovered during an AI-driven whitebox test. Flaws in the ActivityPub federation layer and two-stage templating enabled stored XSS (including admin-view and federated-profile XSS leading to possible full takeover), admin-panel authorization bypass via middleware ordering, private-message reading due to missing signature verification on GET endpoints, mass-assignment post hijacking, unauthenticated category disclosure, and vote manipulation. NodeBB released targeted patches (escaping federated data, middleware reordering, mass-assignment stripping, consistent signature verification) and refactored the templating system in v4.14.0.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
