VDB
Sign up
CRITICAL10.0

GHSA-vh2g-6c4x-5hmp

Path traversal and code execution via prototype vulnerability

Quick fix

GHSA-vh2g-6c4x-5hmp — nodebb: upgrade to the fixed version with the command below.

npm install nodebb@2.8.7

Details

### Impact Due to the use of the [object destructuring assignment](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Operators/Destructuring_assignment) syntax in the user export code path, combined with a path traversal vulnerability, a specially crafted payload could invoke the user export logic to arbitrarily execute javascript files on the local disk.

### Patches Patched in v2.8.7

### Workarounds Site maintainers can cherry pick ec58700f6dff8e5b4af1544f6205ec362b593092 into their codebase to patch the exploit.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/nodebb
Introduced in: 2.5.0Fixed in: 2.8.7
Fixnpm install nodebb@2.8.7

References