Vulnerability record · CVE-2023-43187 · published 27 September 2023
CVE-2023-43187: NodeBB xmlrpc.php XML injection leads to remote code execution
Nodebb · Nodebb
NodeBB forum software before v1.18.6 contains an XML injection flaw (CWE-91) in the xmlrpc.php endpoint that lets attackers execute arbitrary code through crafted XML-RPC requests. It matters because the endpoint is network-reachable and the flaw yields full code execution on the forum host.
Description
A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE with a 9.8 CVSS score and high EPSS probability, with a public exploit reference available.
What it is
NodeBB forum software before v1.18.6 contains an XML injection flaw (CWE-91) in the xmlrpc.php endpoint that lets attackers execute arbitrary code through crafted XML-RPC requests. It matters because the endpoint is network-reachable and the flaw yields full code execution on the forum host.
Impact
An unauthenticated attacker can run arbitrary code on the server, giving full control of the NodeBB instance and any data or credentials it can reach.
Attack surface
Reached over the network via the xmlrpc.php endpoint; the CVSS vector shows no privileges and no user interaction required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.454 (98.7th percentile) and a public exploit reference exists, so exploitation is plausible and should be treated as imminent.
What to do
- Upgrade NodeBB to v1.18.6 or later immediately.
- If patching is delayed, block or restrict access to xmlrpc.php at the reverse proxy or WAF.
- Disable XML-RPC functionality if the forum does not require it.
- Monitor and rate-limit XML-RPC request volume to the endpoint.
- Verify no unauthorized code or web shells were placed on the host after exposure.
Detection
- Alert on POST requests to /xmlrpc.php, especially with unusual XML bodies or oversized payloads.
- Inspect web and application logs for XML-RPC calls followed by unexpected process execution or file writes.
- Hunt for new or modified files under the NodeBB web root and for outbound connections from the forum host.
- Correlate xmlrpc.php access with child processes spawned by the Node.js service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/jagat-singh-chaudhary/CVE/blob/main/CVE-2023-43187 | ExploitThird Party Advisory |
| https://github.com/jagat-singh-chaudhary/CVE/blob/main/CVE-2023-43187 | ExploitThird Party Advisory |
Track CVE-2023-43187 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-43187), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.