CVE-2021-43786

CRITICAL

Nodebb <1.18.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verification step unintentionally allowed master token access to the API. The vulnerability has been patch as of v1.18.5. Users are advised to upgrade as soon as possible.

References (4)

Core 4
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/NodeBB/NodeBB/releases/tag/v1.18.5
Exploit, Third Party Advisory x_refsource_misc
https://blog.sonarsource.com/nodebb-remote-code-execution-with-one-shot/

Scores

CVSS v3 9.8
EPSS 0.0047
EPSS Percentile 64.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (2)
nodebb/nodebb 1.15.0 - 1.18.4
npm/nodebb 1.15.0 - 1.18.5npm
Published Nov 29, 2021
Tracked Since Feb 18, 2026