The record
Written from the 1 report below. Nothing here is unsourced.
- NodeBB, a popular forum software, released version 4.14.2 to fix eight high-severity security vulnerabilities found by Aikido Security's AI pentest agents during a six-hour review.
- The flaws included one that let a regular member reach the admin dashboard without a password, others that exposed private messages and categories to outsiders, and one that allowed attackers to plant malicious links across the site.
- All versions before 4.14.0 are affected, and whether a forum was exposed to all eight depends on whether federation with Mastodon and similar networks was switched on.
- The fixes shipped quietly between May and July, and no attacks using the flaws have been reported.
What to watch next
- Administrators upgrading to 4.14.2 may need to update custom themes and plugins due to the page-handling rebuild in 4.14.0.
- None of the eight flaws has a CVE tracking number yet, and the separate federation flaw CVE-2026-58593 still names no fixed version.
- Aikido's timeline claims conflict with NodeBB's release history, and neither side has explained the discrepancy.
Coverage1
1 report
English national1
All filed from India
Named India · Aikido Security · NodeBB
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
