Vulnerability record · CVE-2022-46164 · published 5 December 2022
CVE-2022-46164: NodeBB socket.io prototype handling allows account takeover
Nodebb · Nodebb
NodeBB uses a plain object with a prototype in socket.io message handling, so a specially crafted payload can impersonate other users and take over accounts. The flaw is network-reachable with no privileges or user interaction required, and it is patched in version 2.6.1.
Description
NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts. This vulnerability has been patched in version 2.6.1. Users are advised to upgrade. Users unable to upgrade may cherry-pick commit `48d143921753914da45926cca6370a92ed0c46b8` into their codebase to patch the exploit.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required and high EPSS probability makes this an urgent account takeover risk.
What it is
NodeBB uses a plain object with a prototype in socket.io message handling, so a specially crafted payload can impersonate other users and take over accounts. The flaw is network-reachable with no privileges or user interaction required, and it is patched in version 2.6.1.
Impact
An unauthenticated attacker can impersonate arbitrary users and take over their accounts, gaining full control of forum identities and any privileges those accounts hold.
Attack surface
Reached over the network through the socket.io message handling path; the CVSS vector indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no public exploit tag is present in the references, but EPSS is high at roughly 0.49 probability (98.8th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Upgrade NodeBB to version 2.6.1 or later.
- If upgrading is not possible, cherry-pick commit 48d143921753914da45926cca6370a92ed0c46b8 into the codebase.
- Restrict or monitor external access to the socket.io endpoint until patched.
- Review forum accounts for signs of unauthorized impersonation or takeover after exposure.
Detection
- Monitor socket.io message traffic for crafted payloads that manipulate object prototypes.
- Alert on unexpected account session or identity changes, especially for privileged accounts.
- Audit authentication and session logs for logins or actions inconsistent with the legitimate account owner.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/NodeBB/NodeBB/commit/48d143921753914da45926cca6370a92ed0c46b8 | PatchThird Party Advisory |
| https://github.com/NodeBB/NodeBB/security/advisories/GHSA-rf3g-v8p5-p675 | PatchThird Party Advisory |
| https://github.com/NodeBB/NodeBB/commit/48d143921753914da45926cca6370a92ed0c46b8 | PatchThird Party Advisory |
| https://github.com/NodeBB/NodeBB/security/advisories/GHSA-rf3g-v8p5-p675 | PatchThird Party Advisory |
Track CVE-2022-46164 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-46164), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.