← Back to browse · API

CVE-2022-46164

Severity
CRITICAL
CVSS
9.4
EPSS
0.48994
Risk score
54.75
CISA KEV
No
PoC
Yes
Published
2022-12-05
Modified
2025-04-23
First seen
2026-08-07
Aliases
EUVD-2022-7733, GHSA-RF3G-V8P5-P675
Products
NodeBB:NodeBB < 2.6.1
Sources
euvd EUVD-2022-7733
packetstorm 37a03ff654fcc82bafa0059f|CVE-2022-46164

Description

NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts. This vulnerability has been patched in version 2.6.1. Users are advised to upgrade. Users unable to upgrade may cherry-pick commit `48d143921753914da45926cca6370a92ed0c46b8` into their codebase to patch the exploit.

References