NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
NodeBB has patched eight security flaws, including vulnerabilities allowing unauthorized admin access and the ability to read private chats, discovered by AI penetration testing. The flaws, some of which stem from the forum's federation with Mastodon and other social sites, were identified in early July and require upgrading to version 4.14.2. While some vulnerabilities didn't require an account, others did, and a separate federation flaw remains unpatched.
NodeBB has addressed eight security vulnerabilities, a discovery made possible by AI penetration testing conducted by Aikido Security. The flaws range from simple settings manipulation to complex account takeover and the ability to access private chat content. The vulnerabilities were identified in early July and require upgrading to version 4.14.2 to resolve them.
Several of the flaws didn't necessitate an account on the target forum. One vulnerability allowed a regular user to redirect their homepage setting to the admin address, effectively gaining admin access without a password. Another allowed an attacker to claim any user account and read private messages one at a time. A third vulnerability involved a flaw in how NodeBB builds its pages, allowing an attacker to inject malicious code into forum posts. The remaining vulnerabilities were related to NodeBB's federation with Mastodon and other social sites, enabling an external server to post and send messages as any local account when federation is enabled.
Aikido Security’s review found that five of the eight vulnerabilities resided in NodeBB’s federation code, impacting forums installed on version 4 by default. Forums upgraded from version 3 had federation automatically switched off, meaning only three of the flaws applied unless an administrator manually re-enabled it. NodeBB’s bug bounty program only pays for work the submitter does themselves, and rejects AI-generated reports.
NodeBB fixed most of the issues quietly, with four fixes released in May, two in June, and a major rebuild of page text handling in 4.14.0 on July 9, which touched 325 files. Aikido Security’s report indicates that some fixes were made earlier, in January 2024, but NodeBB’s release notes name a different change from May. None of the eight vulnerabilities have a CVE tracking number, and no attacks utilizing them have been reported. A separate NodeBB federation flaw, CVE-2026-58593, was filed on July 1, but it is not one of Aikido’s eight and requires federation to be enabled.
