VDB
Sign up
MEDIUM4.6

GHSA-vqr3-vrrg-f3jh

NodeBB Cross-site scripting (XSS) vulnerability

Quick fix

GHSA-vqr3-vrrg-f3jh — nodebb: upgrade to the fixed version with the command below.

npm install nodebb@3.11.1

Details

A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' section of their profile.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/nodebb
Introduced in: 0Fixed in: 3.11.1
Fixnpm install nodebb@3.11.1

References