type: incident ยท created: 2026-07-25 ยท updated: 2026-07-25 ยท tags: [incident, sector-technology] ยท confidence: high ยท affected_sectors: [technology] ยท au_impact: false
NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
Aikido Security's AI pentest agents found eight high-severity flaws in NodeBB forum software in a six-hour source code review. Fixed in version 4.14.2. Flaws included a configuration bypass that let regular members access the admin dashboard.
Overview
| Attribute | Detail |
|---|---|
| Date | 2026-07-24 |
| Product | NodeBB forum software |
| Flaws Found | 8 high-severity vulnerabilities |
| Discovery Method | AI-powered source code review (6 hours) |
| Discoverer | Aikido Security AI pentest agents |
| Fix | NodeBB version 4.14.2 |
Key Findings
- Admin dashboard access bypass: Regular forum members could access the admin dashboard through a configuration bypass
- Private chat exposure: Flaws could expose private messages between users
- Additional high-severity issues: Six more vulnerabilities across authentication, authorisation, and data handling
Significance
This case demonstrates the accelerating capability of AI-powered security agents โ eight high-severity flaws found in a six-hour automated review that might have taken human researchers days or weeks. Similar to how Kimi K3 Agents Found Redis Zero Days And Built Rce Exploit demonstrated AI agents finding Redis zero-days, this reinforces the trend of AI-driven vulnerability discovery in open-source software.