NodeBB SQL Injection vulnerability
High severity
GitHub Reviewed
Published
Aug 27, 2025
to the GitHub Advisory Database
•
Updated Aug 27, 2025
Description
Published by the National Vulnerability Database
Aug 27, 2025
Published to the GitHub Advisory Database
Aug 27, 2025
Reviewed
Aug 27, 2025
Last updated
Aug 27, 2025
NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not properly sanitized, allowing unauthenticated, remote attackers to inject boolean-based blind and PostgreSQL error-based payloads.
References