PatchSiren

HabitRPG CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM HabitRPG CVE published 2026-09-24

CVE-2026-54461

A vulnerability in Habitica, a habit tracker application, allows an authenticated caller to supply a computationally expensive regular expression that degrades application performance or halts Node.js processes. This issue is fixed in version 5.48.2. The vulnerability impacts application performance and availability, requiring defenders to verify exposure and apply the patch promptly. The issue arises fro [truncated]