VYPR
Critical severity9.8NVD Advisory· Published Nov 29, 2021· Updated Jun 17, 2026

CVE-2021-43786

CVE-2021-43786

Description

Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verification step unintentionally allowed master token access to the API. The vulnerability has been patch as of v1.18.5. Users are advised to upgrade as soon as possible.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
nodebbnpm
>= 1.15.0, < 1.18.51.18.5

Affected products

3
  • NodeBB/Nodebb2 versions
    cpe:2.3:a:nodebb:nodebb:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:nodebb:nodebb:*:*:*:*:*:*:*:*range: >=1.15.0,<=1.18.4
    • (no CPE)range: >= 1.15.0, < 1.18.5
  • ghsa-coords
    Range: >= 1.15.0, < 1.18.5

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.