CVE-2024-41962: Yonle Bostr

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Bostr is an nostr relay aggregator proxy that acts like a regular nostr relay. bostr let everyone in even having authorized_keys being set when noscraper is set to true. This vulnerability is fixed in 3.0.10.

Affected products

  • Yonle Bostr: before 3.0.10 (fixed in 3.0.10)

Published 2024-08-01. Last modified 2026-06-17.