CVE-2026-73038: Nodebb
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
NodeBB before 4.15.0 contains a stored cross-site scripting vulnerability in the renderEmoji function that fails to escape tag.icon.url and tag.name attributes. Attackers can deliver malicious ActivityPub Create/Note objects with crafted emoji tags to inject arbitrary HTML and JavaScript into stored post content, executing code in all viewers' browsers.
Affected products
- Nodebb Nodebb: before 4.15.0 (fixed in 4.15.0)
Published 2026-08-13. Last modified 2026-09-24.