Critical severity9.0NVD Advisory· Published Nov 29, 2021· Updated Jun 17, 2026
CVE-2021-43787
CVE-2021-43787
Description
Nodebb is an open source Node.js based forum software. In affected versions a prototype pollution vulnerability in the uploader module allowed a malicious user to inject arbitrary data (i.e. javascript) into the DOM, theoretically allowing for an account takeover when used in conjunction with a path traversal vulnerability disclosed at the same time as this report. The vulnerability has been patched as of v1.18.5. Users are advised to upgrade as soon as possible.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nodebbnpm | >= 1.15.0, < 1.18.5 | 1.18.5 |
Affected products
3Patches
Vulnerability mechanics
References
7- github.com/NodeBB/NodeBB/commit/1783f918bc19568f421473824461ff2ed7755e4cnvdPatchThird Party AdvisoryWEB
- github.com/NodeBB/NodeBB/releases/tag/v1.18.5nvdPatchRelease NotesThird Party AdvisoryWEB
- github.com/NodeBB/NodeBB/security/advisories/GHSA-wx69-rvg3-x7fcnvdPatchThird Party AdvisoryWEB
- blog.sonarsource.com/nodebb-remote-code-execution-with-one-shot/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-wx69-rvg3-x7fcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-43787ghsaADVISORY
- blog.sonarsource.com/nodebb-remote-code-execution-with-one-shotghsaWEB
News mentions
0No linked articles in our index yet.