CRITICAL10.0
GHSA-vh2g-6c4x-5hmp
Path traversal and code execution via prototype vulnerability
Quick fix
GHSA-vh2g-6c4x-5hmp — nodebb: upgrade to the fixed version with the command below.
npm install nodebb@2.8.7Details
### Impact Due to the use of the [object destructuring assignment](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Operators/Destructuring_assignment) syntax in the user export code path, combined with a path traversal vulnerability, a specially crafted payload could invoke the user export logic to arbitrarily execute javascript files on the local disk.
### Patches Patched in v2.8.7
### Workarounds Site maintainers can cherry pick ec58700f6dff8e5b4af1544f6205ec362b593092 into their codebase to patch the exploit.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/NodeBB/NodeBB/security/advisories/GHSA-vh2g-6c4x-5hmp[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-26045[ADVISORY]
- https://github.com/NodeBB/NodeBB/commit/ec58700f6dff8e5b4af1544f6205ec362b593092[WEB]
- https://github.com/NodeBB/NodeBB[PACKAGE]
- https://security.netapp.com/advisory/ntap-20230831-0004[WEB]