CVE Tools

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

The Hacker NewsBy The Hacker News

PatchNodeBB forum software

Our summary

NodeBB has addressed eight high-severity security flaws in its forum software, all identified by AI pentesting tools from Aikido Security during a six-hour audit. All versions prior to 4.14.0 are vulnerable, with the latest patch available in version 4.14.2. The flaws range from allowing unauthenticated users to access private messages and categories, to enabling attackers to inject malicious code through forum posts or federated connections. Some issues required only a regular user account to escalate privileges or bypass protections. While no exploitation has been reported yet, administrators are strongly advised to update immediately due to the potential for serious impacts like unauthorized access and data exposure.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store