Finding eight high-severity vulnerabilities in NodeBB in six hours
ID: e8ef4bfa-d7a0-554f-9260-4b6cdf80e3f9
STIX ID: report--e8ef4bfa-d7a0-554f-9260-4b6cdf80e3f9
Feed Name: Aikido Security's Blog
This technical disclosure describes an autonomous whitebox pentest of NodeBB (pre-4.14.0) that discovered multiple high-severity vulnerabilities — including several XSS vectors (via federated profile icons, federation error logs, and translation/template injection), authorization bypasses exposing admin pages, ActivityPub signature verification flaws allowing user impersonation and private message disclosure, mass-assignment allowing post hijacking, and unauthenticated access to category outboxes. Each issue is explained with proof-of-concept steps and mitigations; maintainers patched the problems in version 4.14.0.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
