Eight security flaws in NodeBB forum software were publicly disclosed on Wednesday, accompanied by exploit code. Aikido Security, which rated all eight as high severity, stated that its AI pentest agents identified these vulnerabilities during a six-hour review of NodeBB's source code.
One flaw allowed a regular forum member to gain access to the admin dashboard by changing their homepage setting to the admin address. Other vulnerabilities enabled unauthorized users to read private messages and access private categories without an account. A significant flaw in how NodeBB builds pages allowed attackers to inject malicious code, leading to cross-site scripting (XSS) attacks when visitors clicked planted links.
Additional flaws permitted attackers to take over existing posts, manipulate vote counts, and execute code via fake servers on the fediverse, which NodeBB forums can join.
All NodeBB versions preceding 4.14.0 are affected by these vulnerabilities. NodeBB has released fixes for all identified issues, and administrators are advised to update their installations to version 4.14.2 immediately. The severity of individual flaws was not rated by NodeBB's release notes, though Aikido Security classified them all as high severity.
The extent of exposure varied depending on the forum's configuration. Five of the eight flaws are located in NodeBB's federation code, which connects forums to social sites like Mastodon. Forums installed fresh on version 4 had all eight vulnerabilities due to default federation. However, forums upgraded from version 3 had federation switched off automatically, meaning only three of the flaws applied unless an administrator manually re-enabled federation.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
NodeBB has released version 4.14.2 to patch eight security flaws, rated high severity by Aikido Security, that could expose admin access and private user data. These vulnerabilities, discovered by AI pentest agents, affect all NodeBB versions prior to 4.14.0 and could allow unauthorized access to administrative functions, private messages, and the injection of malicious code.