CVE-2023-2850: Nodebb

Medium severity, CVSS 4.7. EPSS: 0.3% chance of exploitation in the next 30 days.

NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation of this vulnerability allows certain user information to be extracted by attacker.

Affected products

  • Nodebb Nodebb: before 2.8.13 (fixed in 2.8.13); from 3.0.0, before 3.1.3 (fixed in 3.1.3)

Published 2023-07-25. Last modified 2026-06-17.