🟠 High | Source: The Hacker News
Eight high-severity vulnerabilities in NodeBB forum software were publicly disclosed alongside working exploit code, after Aikido Security’s AI-powered penetration testing agents discovered them in a six-hour automated source code review. The flaws expose administrator access and private chat messages across all NodeBB versions prior to 4.14.0. NodeBB has patched all eight issues and administrators should upgrade to version 4.14.2 immediately.
Security Architect’s Take: If NodeBB is deployed anywhere in your environment — including self-hosted developer portals, community platforms, or internal forums — upgrade to 4.14.2 without delay, as exploit code is already public. Audit your deployment inventory to confirm no instances are internet-facing on an unpatched version.
Original advisory: NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats