CVE Tools
Back to feed
Patch released NodeBB forum software privilege-escalation NodeBB web-app

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

The Hacker News·By The Hacker News··4 min read
CVE Tools coverage

NodeBB has addressed eight high-severity security flaws in its forum software, all identified by AI pentesting tools from Aikido Security during a six-hour audit. All versions prior to 4.14.0 are vulnerable, with the latest patch available in version 4.14.2. The flaws range from allowing unauthenticated users to access private messages and categories, to enabling attackers to inject malicious code through forum posts or federated connections. Some issues required only a regular user account to escalate privileges or bypass protections. While no exploitation has been reported yet, administrators are strongly advised to update immediately due to the potential for serious impacts like unauthorized access and data exposure.