Description
Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1, any authenticated user can immediately obtain full administrative control of the entire Neko instance (member management, room settings, broadcast control, session termination, etc.). This results in a complete compromise of the instance. The vulnerability has been patched in v3.0.11 and v3.1.2. If upgrading is not immediately possible, the following mitigations can reduce risk: Restrict access to trusted users only (avoid granting accounts to untrusted parties); ensure all user passwords are strong and only shared with trusted individuals; run the instance only when needed; avoid leaving it continuously exposed; place the instance behind authentication layers such as a reverse proxy with additional access controls; disable or restrict access to the /api/profile endpoint if feasible; and/or monitor for suspicious privilege changes or unexpected administrative actions. Note that these are temporary mitigations and do not fully eliminate the vulnerability. Upgrading is strongly recommended.
Published: 2026-04-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Urgent Patch
AI Analysis

Impact

Neko, a self-hosted virtual browser, has a flaw that lets any authenticated user gain full administrative control over the entire instance, including member management, room settings, broadcast control, and session termination. This gives the attacker complete compromise of the instance. The weakness is reflected in multiple CWE identifiers, such as unchecked input (CWE‑20) and missing access control (CWE‑269, CWE‑284, CWE‑639, CWE‑862).

Affected Systems

The affected product is Neko from m1k1o. Versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 are vulnerable. The issue has been patched in releases v3.0.11 and v3.1.2.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity vulnerability. The exploit requires only a legitimate authenticated session; an attacker who can log in can perform privileged operations via the web interface or API. Although no EPSS score is available and it is not listed in the CISA KEV catalog, the impact of a successful exploit is total administrative takeover of the instance. Because the vulnerability is driven by the attacker’s credential, the attack vector is likely evaluated as authenticated. Typical environments that expose Neko to the public internet face a higher risk, especially if weak or shared passwords, or unrestricted reverse proxies, are present.

Generated by OpenCVE AI on April 21, 2026 at 15:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch by upgrading Neko to version 3.0.11 or later, including 3.1.2 and beyond.
  • If an immediate upgrade is not possible, limit the instance to trusted users only, enforce strong, unique passwords, and run the service only when necessary.
  • Deploy the instance behind a reverse proxy with additional access controls, disable or tightly restrict access to the /api/profile endpoint, and monitor for unauthorized privilege changes or unexpected administrative actions.

Generated by OpenCVE AI on April 21, 2026 at 15:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2gw9-c2r2-f5qf Neko has a Self-service Privilege Escalation for Authenticated Users
History

Thu, 23 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:m1k1o:neko:*:*:*:*:*:*:*:*

Wed, 22 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared M1k1o
M1k1o neko
Vendors & Products M1k1o
M1k1o neko

Tue, 21 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Apr 2026 01:15:00 +0000

Type Values Removed Values Added
Description Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1, any authenticated user can immediately obtain full administrative control of the entire Neko instance (member management, room settings, broadcast control, session termination, etc.). This results in a complete compromise of the instance. The vulnerability has been patched in v3.0.11 and v3.1.2. If upgrading is not immediately possible, the following mitigations can reduce risk: Restrict access to trusted users only (avoid granting accounts to untrusted parties); ensure all user passwords are strong and only shared with trusted individuals; run the instance only when needed; avoid leaving it continuously exposed; place the instance behind authentication layers such as a reverse proxy with additional access controls; disable or restrict access to the /api/profile endpoint if feasible; and/or monitor for suspicious privilege changes or unexpected administrative actions. Note that these are temporary mitigations and do not fully eliminate the vulnerability. Upgrading is strongly recommended.
Title Neko has Self-service Privilege Escalation for Authenticated Users
Weaknesses CWE-20
CWE-269
CWE-284
CWE-639
CWE-862
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-04-22T03:56:19.795Z

Reserved: 2026-04-06T22:06:40.515Z

Link: CVE-2026-39386

cve-icon Vulnrichment

Updated: 2026-04-21T13:33:50.593Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-21T01:16:06.217

Modified: 2026-04-23T18:21:32.620

Link: CVE-2026-39386

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T11:47:00Z