← Vulnerability feed

Vulnerability record · CVE-2022-36076 · published 2 September 2022

CVE-2022-36076: Nodebb cross-site request forgery vulnerability

Nodebb · Nodebb

NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. Due to an unnecessarily strict conditional in the code handling the first step of the SSO process, the pre-existing logic that added (and later checked) a nonce was inadvertently rendered opt-in instead of opt-out. This re-exposed a vulnerability in that a specially crafted Man-in-the-Middle (MITM) attack could theoretically take over another user account during the single sign-on process. The issue has been fully patched in version 1.17.2.

7.5 CVSS 3.1 High EPSS 0.56% · top 55.3% CWE-352 · Cross-site request forgery
7.5CVSS 3.1 base score
0.56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. Due to an unnecessarily strict conditional in the code handling the first step of the SSO process, the pre-existing logic that added (and later checked) a nonce was inadvertently rendered opt-in instead of opt-out. This re-exposed a vulnerability in that a specially crafted Man-in-the-Middle (MITM) attack could theoretically take over another user account during the single sign-on process. The issue has been fully patched in version 1.17.2.

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-36076 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2020-15149Nodebb improper privilege management vulnerabilityNodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user…EPSS 2.4%9.8CVE-2023-43187NodeBB xmlrpc.php XML injection leads to remote code executionNodeBB forum software before v1.18.6 contains an XML injection flaw (CWE-91) in the xmlrpc.php endpoint that lets attackers execute arbitrary code th…EPSS 45%analysed9.8CVE-2023-26045Nodebb path traversal vulnerabilityNodeBB is Node.js based forum software. Starting in version 2.5.0 and prior to version 2.8.7, due to the use of the object destructuring assignment s…EPSS 1.0%9.8CVE-2022-46164NodeBB socket.io prototype handling allows account takeoverNodeBB uses a plain object with a prototype in socket.io message handling, so a specially crafted payload can impersonate other users and take over a…EPSS 49%analysed9.8CVE-2022-36045Nodebb vulnerabilityNodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets for instant interac…EPSS 1.3%8.7CVE-2026-58593Nodebb authentication bypass by spoofing vulnerabilityNodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound middleware verifies the HTTP-…EPSS 0.29%8.6CVE-2025-50979Nodebb sql injection vulnerabilityNodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not pro…EPSS 8.5%7.5CVE-2023-30591NodeBB Socket.IO event name type confusion denial of serviceNodeBB versions up to and including v2.8.10 crash when processing crafted Socket.IO messages whose event name is an array or object instead of a stri…EPSS 54%analysed

Source: NIST National Vulnerability Database (record CVE-2022-36076), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.