CVE-2026-54461: Habitrpg Habitica

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Habitica is a habit tracker application that treats goals like a role-playing game. From 4.172.1 until 5.48.2, a query parameter on Habitica's /api/v3/groups/:groupId/members route is not sanitized before being interpreted as a regular expression. An authenticated caller can supply a computationally expensive regular expression that degrades application performance or halts Node.js processes. This issue is fixed in version 5.48.2.

Affected products

  • Habitrpg Habitica: from 4.172.1, before 5.48.2 (fixed in 5.48.2)

Published 2026-09-24. Last modified 2026-09-30.