logo

Finding eight high-severity vulnerabilities in NodeBB in six hours

ID: e8ef4bfa-d7a0-554f-9260-4b6cdf80e3f9

STIX ID: report--e8ef4bfa-d7a0-554f-9260-4b6cdf80e3f9

Feed Name: Aikido Security's Blog

Threat Score
75/100

Date Published: 2026-07-22

Date Updated: 2026-07-24

...
...

This technical disclosure describes an autonomous whitebox pentest of NodeBB (pre-4.14.0) that discovered multiple high-severity vulnerabilities — including several XSS vectors (via federated profile icons, federation error logs, and translation/template injection), authorization bypasses exposing admin pages, ActivityPub signature verification flaws allowing user impersonation and private message disclosure, mass-assignment allowing post hijacking, and unauthenticated access to category outboxes. Each issue is explained with proof-of-concept steps and mitigations; maintainers patched the problems in version 4.14.0.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.