{"id":"CVE-2021-43787","aliases":["GHSA-wx69-rvg3-x7fc"],"url":"https://o3.security/vulnerability/CVE-2021-43787","summary":"XSS via prototype pollution in NodeBB ","details":"Nodebb is an open source Node.js based forum software. In affected versions a prototype pollution vulnerability in the uploader module allowed a malicious user to inject arbitrary data (i.e. javascript) into the DOM, theoretically allowing for an account takeover when used in conjunction with a path traversal vulnerability disclosed at the same time as this report. The vulnerability has been patched as of v1.18.5. Users are advised to upgrade as soon as possible.","published":"2021-11-29T20:15:08.190Z","modified":"2026-07-09T11:24:15.513207Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"nodebb","fixedVersion":"1.18.5"}],"fix":{"url":"https://github.com/NodeBB/NodeBB/commit/1783f918bc19568f421473824461ff2ed7755e4c","label":"NodeBB/NodeBB@1783f91"},"references":[{"type":"FIX","url":"https://github.com/NodeBB/NodeBB/commit/1783f918bc19568f421473824461ff2ed7755e4c"},{"type":"FIX","url":"https://github.com/NodeBB/NodeBB/releases/tag/v1.18.5"},{"type":"FIX","url":"https://github.com/NodeBB/NodeBB/security/advisories/GHSA-wx69-rvg3-x7fc"},{"type":"EVIDENCE","url":"https://blog.sonarsource.com/nodebb-remote-code-execution-with-one-shot/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T11:24:15.513207Z"}}