Nodebb is an open source Node.js based forum software. Prior to v1.18.5, a path traversal vulnerability was present that allowed users to access JSON files outside of the expected `languages/` directory. The vulnerability has been patched as of v1.18.5. Users are advised to upgrade as soon as possible.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2021-2372 | Nodebb is an open source Node.js based forum software. Prior to v1.18.5, a path traversal vulnerability was present that allowed users to access JSON files outside of the expected `languages/` directory. The vulnerability has been patched as of v1.18.5. Users are advised to upgrade as soon as possible. |
![]() |
GHSA-pfj7-2qfw-vwgm | NodeBB vulnerable to path traversal in translator module |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T04:03:08.978Z
Reserved: 2021-11-16T00:00:00
Link: CVE-2021-43788

No data.

Status : Modified
Published: 2021-11-29T20:15:08.253
Modified: 2024-11-21T06:29:47.450
Link: CVE-2021-43788

No data.

No data.