CVE Feed

    Dashboard / CVE / CVE-2022-23602

    CVE-2022-23602

    Nimforum is a lightweight alternative to Discourse written in Nim. In versions prior to 2.2.0 any forum user can create a new thread/post with an include referencing a file local to the host operating system. Nimforum will render the file if able. This can also be done silently by using NimForum's post "preview" endpoint. Even if NimForum is running as a non-critical user, the forum.json secrets can be stolen. Version 2.2.0 of NimForum includes patches for this vulnerability. Users are advised to upgrade as soon as is possible. There are no known workarounds for this issue.

    Published:Feb 1, 2022
    Last Modified:May 5, 2025
    EPS:Feb 1, 2022
    EPSS Score:0.00386
    CVSS Score:7.7

    Affected Products

    Vendor
    Nim-lang
    Product
    Docutils
    Vendor
    Nim-lang
    Product
    Nimforum

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High