PatchSiren

NodeBB CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM NodeBB CVE published 2026-08-13

CVE-2026-73038

CVE-2026-73038 is a stored cross-site scripting vulnerability in NodeBB before version 4.15.0. The renderEmoji function fails to escape tag.icon.url and tag.name attributes, allowing attackers to inject arbitrary HTML and JavaScript into stored post content via malicious ActivityPub Create/Note objects with crafted emoji tags. This executes code in all viewers' browsers.

HIGH NodeBB CVE published 2026-07-01

CVE-2026-58593

CVE-2026-58593 is a high-severity vulnerability in NodeBB's ActivityPub implementation. The issue allows a remote attacker to forge posts and direct messages attributed to arbitrary local users by exploiting the lack of validation for the 'attributedTo' field in inbound ActivityPub objects. This vulnerability has a CVSS score of 8.7 and is classified as HIGH. Administrators and users of NodeBB instances w [truncated]