Impact
NodeBB versions earlier than 4.15.0 contain a stored cross‑site scripting flaw in the renderEmoji routine that fails to escape the tag.icon.url and tag.name attributes. Attackers can embed malicious ActivityPub Create/Note objects with crafted emoji tags, inserting arbitrary HTML and JavaScript into stored post content. When users view the affected content, the injected code executes in their browsers, potentially allowing session hijacking, data theft, or defacement. The vulnerability directly impacts confidentiality, integrity, and availability for all viewers of the compromised posts.
Affected Systems
The affected product is NodeBB, specifically all releases prior to 4.15.0. No additional vendor or product variations are listed. Users running any NodeBB instance below that version are exposed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker sending malicious ActivityPub messages to the forum; the vulnerability can be triggered by any user who receives or views the note, making the risk largely opportunistic. Given the nature of stored XSS, a single compromised post can affect many users, though the lack of an exploit probability metric suggests there is no known active exploitation activity.
OpenCVE Enrichment