Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-25 ยท updated: 2026-07-25 ยท tags: [incident, sector-technology] ยท confidence: high ยท affected_sectors: [technology] ยท au_impact: false

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

Aikido Security's AI pentest agents found eight high-severity flaws in NodeBB forum software in a six-hour source code review. Fixed in version 4.14.2. Flaws included a configuration bypass that let regular members access the admin dashboard.

Overview

Attribute Detail
Date 2026-07-24
Product NodeBB forum software
Flaws Found 8 high-severity vulnerabilities
Discovery Method AI-powered source code review (6 hours)
Discoverer Aikido Security AI pentest agents
Fix NodeBB version 4.14.2

Key Findings

  • Admin dashboard access bypass: Regular forum members could access the admin dashboard through a configuration bypass
  • Private chat exposure: Flaws could expose private messages between users
  • Additional high-severity issues: Six more vulnerabilities across authentication, authorisation, and data handling

Significance

This case demonstrates the accelerating capability of AI-powered security agents โ€” eight high-severity flaws found in a six-hour automated review that might have taken human researchers days or weeks. Similar to how Kimi K3 Agents Found Redis Zero Days And Built Rce Exploit demonstrated AI agents finding Redis zero-days, this reinforces the trend of AI-driven vulnerability discovery in open-source software.