hacker-news · Crawled Jul 24, 2026

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

1 CVEs
Read original article ↗

AI Summary

NodeBB patched eight high-severity vulnerabilities discovered by AI-powered pentesting tools, affecting all versions prior to 4.14.0. The flaws enable privilege escalation, private message access, unauthorized admin dashboard access, and cross-site scripting via malicious links in forum content. Five of the vulnerabilities are tied to federation functionality with the fediverse, and while no active exploitation has been reported, administrators are urged to upgrade to version 4.14.2 due to the critical nature of the exposures.

AI-extracted · verify before operational use

Extracted Entities 1 found

MITRE ATT&CK TTPs 4 techniques