VYPR
Critical severity9.4NVD Advisory· Published Dec 5, 2022· Updated Jun 17, 2026

CVE-2022-46164

CVE-2022-46164

Description

NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts. This vulnerability has been patched in version 2.6.1. Users are advised to upgrade. Users unable to upgrade may cherry-pick commit 48d143921753914da45926cca6370a92ed0c46b8 into their codebase to patch the exploit.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
nodebbnpm
< 2.6.12.6.1

Affected products

3
  • NodeBB/Nodebbcpe-rescue2 versions
    < 2.6.1+ 1 more
    • (no CPE)range: < 2.6.1
    • cpe:2.3:a:nodebb:nodebb:*:*:*:*:*:*:*:*range: <2.6.1
  • ghsa-coords
    Range: < 2.6.1

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.