VDB
Sign up
CRITICAL9.4

GHSA-rf3g-v8p5-p675

NodeBB vulnerable to account takeover via prototype vulnerability

Quick fix

GHSA-rf3g-v8p5-p675 — nodebb: upgrade to the fixed version with the command below.

npm install nodebb@2.6.1

Details

### Impact Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts.

### Patches Patched in 2.6.1

### Workarounds Site maintainers can cherry-pick https://github.com/NodeBB/NodeBB/commit/48d143921753914da45926cca6370a92ed0c46b8 into their codebase to patch the exploit.

### For more information If you have any questions or comments about this advisory:

Discuss it on [our community forum](https://github.com/NodeBB/NodeBB/security/advisories/community.nodebb.org/) Email us at [support@nodebb.org](mailto:support@nodebb.org)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/nodebb
Introduced in: 0Fixed in: 2.6.1
Fixnpm install nodebb@2.6.1

References