CVE-2025-29513
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2025-29513 is a Cross-Site Scripting (XSS) vulnerability affecting NodeBB versions 4.0.4 and older. This issue allows remote attackers to inject malicious code into the admin API Access token generator. Successful exploitation could result in unauthorized access to administrative functions or data within the NodeBB platform. Users are strongly encouraged to update their installations to the latest version to mitigate this risk. The XSS vulnerability could potentially be used to steal sensitive information or carry out further attacks on unsuspecting users.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- NodeBB
Affected Vendors
- Nodebb