← Vulnerability feed

Vulnerability record · CVE-2022-46164 · published 5 December 2022

CVE-2022-46164: NodeBB socket.io prototype handling allows account takeover

Nodebb · Nodebb

NodeBB uses a plain object with a prototype in socket.io message handling, so a specially crafted payload can impersonate other users and take over accounts. The flaw is network-reachable with no privileges or user interaction required, and it is patched in version 2.6.1.

9.8 CVSS 3.1 Critical EPSS 49% · top 1.2% CWE-665 · CWE-665
9.8CVSS 3.1 base score
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts. This vulnerability has been patched in version 2.6.1. Users are advised to upgrade. Users unable to upgrade may cherry-pick commit `48d143921753914da45926cca6370a92ed0c46b8` into their codebase to patch the exploit.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required and high EPSS probability makes this an urgent account takeover risk.

What it is

NodeBB uses a plain object with a prototype in socket.io message handling, so a specially crafted payload can impersonate other users and take over accounts. The flaw is network-reachable with no privileges or user interaction required, and it is patched in version 2.6.1.

Impact

An unauthenticated attacker can impersonate arbitrary users and take over their accounts, gaining full control of forum identities and any privileges those accounts hold.

Attack surface

Reached over the network through the socket.io message handling path; the CVSS vector indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no public exploit tag is present in the references, but EPSS is high at roughly 0.49 probability (98.8th percentile), indicating elevated likelihood of attempted exploitation.

What to do

  • Upgrade NodeBB to version 2.6.1 or later.
  • If upgrading is not possible, cherry-pick commit 48d143921753914da45926cca6370a92ed0c46b8 into the codebase.
  • Restrict or monitor external access to the socket.io endpoint until patched.
  • Review forum accounts for signs of unauthorized impersonation or takeover after exposure.

Detection

  • Monitor socket.io message traffic for crafted payloads that manipulate object prototypes.
  • Alert on unexpected account session or identity changes, especially for privileged accounts.
  • Audit authentication and session logs for logins or actions inconsistent with the legitimate account owner.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-46164 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2020-15149Nodebb improper privilege management vulnerabilityNodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user…EPSS 2.4%9.8CVE-2023-43187NodeBB xmlrpc.php XML injection leads to remote code executionNodeBB forum software before v1.18.6 contains an XML injection flaw (CWE-91) in the xmlrpc.php endpoint that lets attackers execute arbitrary code th…EPSS 45%analysed9.8CVE-2023-26045Nodebb path traversal vulnerabilityNodeBB is Node.js based forum software. Starting in version 2.5.0 and prior to version 2.8.7, due to the use of the object destructuring assignment s…EPSS 1.0%9.8CVE-2022-36045Nodebb vulnerabilityNodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets for instant interac…EPSS 1.3%8.7CVE-2026-58593Nodebb authentication bypass by spoofing vulnerabilityNodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound middleware verifies the HTTP-…EPSS 0.29%8.6CVE-2025-50979Nodebb sql injection vulnerabilityNodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not pro…EPSS 8.5%7.5CVE-2023-30591NodeBB Socket.IO event name type confusion denial of serviceNodeBB versions up to and including v2.8.10 crash when processing crafted Socket.IO messages whose event name is an array or object instead of a stri…EPSS 54%analysed7.5CVE-2022-36076Nodebb cross-site request forgery vulnerabilityNodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. Due to an unnecessarily strict conditional …EPSS 0.56%

Source: NIST National Vulnerability Database (record CVE-2022-46164), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.