CVE Feed

    Dashboard / CVE / CVE-2023-26045

    CVE-2023-26045

    NodeBB is Node.js based forum software. Starting in version 2.5.0 and prior to version 2.8.7, due to the use of the object destructuring assignment syntax in the user export code path, combined with a path traversal vulnerability, a specially crafted payload could invoke the user export logic to arbitrarily execute javascript files on the local disk. This issue is patched in version 2.8.7. As a workaround, site maintainers can cherry pick the fix into their codebase to patch the exploit.

    Published:Jul 24, 2023
    Last Modified:Feb 13, 2025
    EPS:Jul 24, 2023
    EPSS Score:0.00304
    CVSS Score:10

    Affected Products

    Vendor
    Nodebb
    Product
    Nodebb

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High