Eight security flaws in NodeBB were disclosed on July 24, 2026, along with exploit code. Discovered by Aikido Security’s AI pentest agents in a six-hour source code review, all eight are rated high severity. Every version before 4.14.0 is affected; NodeBB has fixed them in version 4.14.2.
The vulnerabilities range from a simple settings change allowing a regular forum member to access the admin dashboard, to flaws enabling unauthenticated attackers to read private messages and private categories. The most severe flaw involves page-building logic that allows cross-site scripting via user input. Three flaws require no account, two need a member account, and three require user interaction. Five of the eight are in NodeBB’s federation code, affecting forums with federation enabled.
NodeBB patched most flaws quietly: four in May, two in June, and the largest (a rebuild of page text handling) in version 4.14.0 on July 9. Administrators should upgrade to 4.14.2. None of the eight have CVE IDs, and no active attacks have been reported. A separate federation flaw, CVE-2026-58593, exists but is not among the eight.
CVEs: CVE-2026-58593
Companies: NodeBB, Aikido Security
Products: NodeBB
Original source: thehackernews.com