<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Nodejs — PoC Archive</title><link>https://poc.intelseclab.com/tags/nodejs/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 06 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/nodejs/index.xml" rel="self" type="application/rss+xml"/><item><title>React Server Components Flight-Protocol Prototype Pollution RCE — "React2Shell" (CVE-2025-55182)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-55182-react-server-components-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-55182-react-server-components-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-55182. Status: PoC. Affects: React Server Components (RSC) packages using the Flight protocol (commonly deployed via Next.js). Tags: react, react-server-components, rsc, flight-protocol, prototype-pollution, deserialization, unauthenticated-rce, nextjs, nodejs, python.</description><category>web</category><category>Critical</category><category>react</category><category>react-server-components</category><category>rsc</category><category>flight-protocol</category><category>prototype-pollution</category><category>deserialization</category><category>unauthenticated-rce</category><category>nextjs</category><category>nodejs</category><category>python</category></item><item><title>Mongoose `populate()` Match `$where` Bypass Command Injection (CVE-2025-23061)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-23061-mongoose-command-injection/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-23061-mongoose-command-injection/</guid><description>Critical severity (CVSS 9) — web · CVE-2025-23061. Status: Weaponized. Affects: Mongoose (Node.js MongoDB ODM). Tags: mongoose, nodejs, nosql-injection, mongodb, populate, where-operator, command-injection, rce, cwe-943, cwe-94, express.</description><category>web</category><category>Critical</category><category>mongoose</category><category>nodejs</category><category>nosql-injection</category><category>mongodb</category><category>populate</category><category>where-operator</category><category>command-injection</category><category>rce</category><category>cwe-943</category><category>cwe-94</category><category>express</category></item><item><title>WebSocket Authentication Brute-Force via Missing Rate Limiting (CVE-2026-27778)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27778-websocket-auth-bruteforce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27778-websocket-auth-bruteforce/</guid><description>Medium severity — web · CVE-2026-27778. Status: PoC. Affects: Generic Node.js/Express + ws WebSocket authentication server (demonstration/simulator app). Tags: websocket, brute-force, cwe-307, rate-limiting, authentication, nodejs, simulator.</description><category>web</category><category>Medium</category><category>websocket</category><category>brute-force</category><category>cwe-307</category><category>rate-limiting</category><category>authentication</category><category>nodejs</category><category>simulator</category></item><item><title>Supply Chain Command Injection in AWS CDK's NodejsFunction — CVE-2026-11417</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-11417-aws-cdk-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-11417-aws-cdk-rce/</guid><description>High severity (CVSS 3.1) — cloud · CVE-2026-11417. Status: PoC. Affects: aws-cdk-lib (npm package), NodejsFunction L2 construct. Tags: aws, cdk, supply-chain, command-injection, esbuild, nodejs, ci-cd, rce.</description><category>cloud</category><category>High</category><category>aws</category><category>cdk</category><category>supply-chain</category><category>command-injection</category><category>esbuild</category><category>nodejs</category><category>ci-cd</category><category>rce</category></item><item><title>Sequelize ORM JSON Cast SQL Injection — CVE-2026-30951</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-30951-sequelize-json-cast-sqli/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-30951-sequelize-json-cast-sqli/</guid><description>High severity — web · CVE-2026-30951. Status: PoC. Affects: Sequelize ORM v6 (Node.js). Tags: sequelize, sqli, orm, json-cast, nodejs, express, sqlite, boolean-based.</description><category>web</category><category>High</category><category>sequelize</category><category>sqli</category><category>orm</category><category>json-cast</category><category>nodejs</category><category>express</category><category>sqlite</category><category>boolean-based</category></item><item><title>Postiz Arbitrary File Upload to Stored XSS / Account Takeover (CVE-2026-40487)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40487-postiz-svg-upload-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40487-postiz-svg-upload-xss/</guid><description>High severity (CVSS 8.9) — web · CVE-2026-40487 / GHSA-44wg-r34q-hvfx. Status: PoC. Affects: Postiz (open-source social media management platform, gitroomhq/postiz-app). Tags: file-upload, mime-spoofing, stored-xss, account-takeover, postiz, nodejs, oauth-backdoor.</description><category>web</category><category>High</category><category>file-upload</category><category>mime-spoofing</category><category>stored-xss</category><category>account-takeover</category><category>postiz</category><category>nodejs</category><category>oauth-backdoor</category></item><item><title>PolarLearn Forum Vote Count Manipulation (CVE-2026-25126)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25126-polarlearn-vote-manipulation/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25126-polarlearn-vote-manipulation/</guid><description>Medium severity — web · CVE-2026-25126. Status: PoC. Affects: PolarLearn forum platform. Tags: business-logic, vote-manipulation, input-validation, api-abuse, forum, nodejs, ghost-downvote.</description><category>web</category><category>Medium</category><category>business-logic</category><category>vote-manipulation</category><category>input-validation</category><category>api-abuse</category><category>forum</category><category>nodejs</category><category>ghost-downvote</category></item><item><title>Orval OpenAPI Codegen Arbitrary Code Execution via Malicious Spec (CVE-2026-23947)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-23947-orval-codegen-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-23947-orval-codegen-rce/</guid><description>High severity — misc · CVE-2026-23947. Status: PoC. Affects: Orval (OpenAPI-to-TypeScript client generator), version 7.10.0. Tags: orval, openapi, code-generation, arbitrary-code-execution, nodejs, supply-chain, typescript, build-tooling.</description><category>misc</category><category>High</category><category>orval</category><category>openapi</category><category>code-generation</category><category>arbitrary-code-execution</category><category>nodejs</category><category>supply-chain</category><category>typescript</category><category>build-tooling</category></item><item><title>oRPC OpenAPI Reference Plugin Stored XSS via Unescaped Spec Embedding (CVE-2026-33331)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33331-orpc-openapi-stored-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33331-orpc-openapi-stored-xss/</guid><description>High severity — web · CVE-2026-33331 (GHSA-7f6v-3gx7-27q8). Status: PoC. Affects: middleapi/orpc — OpenAPI documentation reference plugin (packages/openapi/src/plugins/openapi-reference.ts). Tags: xss, stored-xss, orpc, openapi, cwe-79, javascript, nodejs, docs-page.</description><category>web</category><category>High</category><category>xss</category><category>stored-xss</category><category>orpc</category><category>openapi</category><category>cwe-79</category><category>javascript</category><category>nodejs</category><category>docs-page</category></item><item><title>npm `tar` Package Unicode-Normalization Race Condition / File Collision (CVE-2026-2395)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-2395-tar-race-condition/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-2395-tar-race-condition/</guid><description>Medium severity — misc · CVE-2026-2395. Status: PoC. Affects: tar npm package. Tags: tar, nodejs, npm, race-condition, unicode-normalization, file-collision, archive-extraction, data-corruption.</description><category>misc</category><category>Medium</category><category>tar</category><category>nodejs</category><category>npm</category><category>race-condition</category><category>unicode-normalization</category><category>file-collision</category><category>archive-extraction</category><category>data-corruption</category></item><item><title>Node.js protobufjs Dynamic Type Compilation RCE (CVE-2026-41242)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-41242-protobufjs-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-41242-protobufjs-rce/</guid><description>Critical severity — web · CVE-2026-41242. Status: PoC. Affects: Node.js application using protobufjs (Root.fromJSON + dynamic decode). Tags: nodejs, protobufjs, rce, deserialization, express, code-injection, javascript.</description><category>web</category><category>Critical</category><category>nodejs</category><category>protobufjs</category><category>rce</category><category>deserialization</category><category>express</category><category>code-injection</category><category>javascript</category></item><item><title>Node.js `tar` Package Symlink Path Traversal — CVE-2026-29786</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-29786-node-tar-symlink-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-29786-node-tar-symlink-traversal/</guid><description>High severity — misc · CVE-2026-29786. Status: PoC. Affects: tar npm package (Node.js). Tags: node-tar, path-traversal, symlink, archive-extraction, arbitrary-file-write, nodejs, supply-chain.</description><category>misc</category><category>High</category><category>node-tar</category><category>path-traversal</category><category>symlink</category><category>archive-extraction</category><category>arbitrary-file-write</category><category>nodejs</category><category>supply-chain</category></item><item><title>node-tar Hardlink/Symlink Path Traversal Arbitrary File Overwrite (CVE-2026-23745)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-23745-node-tar-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-23745-node-tar-path-traversal/</guid><description>High severity — misc · CVE-2026-23745 / GHSA-8qq5-rm4j-mr97. Status: PoC. Affects: node-tar (npm package tar). Tags: node-tar, path-traversal, arbitrary-file-overwrite, hardlink, symlink, supply-chain, nodejs, tar-archive.</description><category>misc</category><category>High</category><category>node-tar</category><category>path-traversal</category><category>arbitrary-file-overwrite</category><category>hardlink</category><category>symlink</category><category>supply-chain</category><category>nodejs</category><category>tar-archive</category></item><item><title>Next.js Vendored picomatch Vulnerable Dependency — CVE-2026-33671</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33671-nextjs-vendored-picomatch-dep/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33671-nextjs-vendored-picomatch-dep/</guid><description>High severity — web · CVE-2026-33671. Status: PoC. Affects: Next.js 16.2.4 (bundles picomatch 4.0.3 at node_modules/next/dist/compiled/picomatch/). Tags: nextjs, picomatch, vendored-dependency, supply-chain, sca-bypass, trivy, nodejs, dependency-scanning.</description><category>web</category><category>High</category><category>nextjs</category><category>picomatch</category><category>vendored-dependency</category><category>supply-chain</category><category>sca-bypass</category><category>trivy</category><category>nodejs</category><category>dependency-scanning</category></item><item><title>Multiparty Denial of Service via Prototype-Pollution Field Name (CVE-2026-8161)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-8161-multiparty-prototype-pollution-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-8161-multiparty-prototype-pollution-dos/</guid><description>Medium severity — misc · CVE-2026-8161 / GHSA-qxch-whhj-8956. Status: PoC. Affects: multiparty (npm package, multipart/form-data parser). Tags: multiparty, nodejs, prototype-pollution, denial-of-service, cwe-1321, uncaught-exception, multipart-parser.</description><category>misc</category><category>Medium</category><category>multiparty</category><category>nodejs</category><category>prototype-pollution</category><category>denial-of-service</category><category>cwe-1321</category><category>uncaught-exception</category><category>multipart-parser</category></item><item><title>Multer Orphaned Temporary File Disk-Exhaustion DoS — CVE-2026-3304</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3304-multer-orphaned-file-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3304-multer-orphaned-file-dos/</guid><description>High severity (CVSS 8.7) — web · CVE-2026-3304. Status: PoC. Affects: Multer (Node.js multipart/form-data middleware for Express). Tags: multer, nodejs, express, dos, file-upload, orphaned-file, disk-exhaustion, multipart.</description><category>web</category><category>High</category><category>multer</category><category>nodejs</category><category>express</category><category>dos</category><category>file-upload</category><category>orphaned-file</category><category>disk-exhaustion</category><category>multipart</category></item><item><title>MikroORM Custom Type Raw SQL Injection (CVE-2026-34220)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34220-mikroorm-sql-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34220-mikroorm-sql-injection/</guid><description>High severity — web · CVE-2026-34220. Status: PoC. Affects: MikroORM (Node.js/TypeScript ORM). Tags: sql-injection, mikroorm, nodejs, typescript, orm, docker, database.</description><category>web</category><category>High</category><category>sql-injection</category><category>mikroorm</category><category>nodejs</category><category>typescript</category><category>orm</category><category>docker</category><category>database</category></item><item><title>Math.js Expression Parser Sandbox Bypass RCE (CVE-2026-40897)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40897-mathjs-sandbox-bypass-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40897-mathjs-sandbox-bypass-rce/</guid><description>Critical severity — web · CVE-2026-40897. Status: Weaponized. Affects: Math.js expression parser (Node.js library). Tags: mathjs, nodejs, sandbox-bypass, rce, expression-parser, prototype-pollution-adjacent, reverse-shell, javascript.</description><category>web</category><category>Critical</category><category>mathjs</category><category>nodejs</category><category>sandbox-bypass</category><category>rce</category><category>expression-parser</category><category>prototype-pollution-adjacent</category><category>reverse-shell</category><category>javascript</category></item><item><title>LiquidJS Template Engine Path Traversal — CVE-2026-30952</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-30952-liquidjs-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-30952-liquidjs-path-traversal/</guid><description>High severity (CVSS 8.7) — misc · CVE-2026-30952 (GHSA-wmfp-5q7x-987x). Status: PoC. Affects: liquidjs npm package (LiquidJS template engine). Tags: liquidjs, path-traversal, template-engine, arbitrary-file-read, nodejs, library, ssti-adjacent.</description><category>misc</category><category>High</category><category>liquidjs</category><category>path-traversal</category><category>template-engine</category><category>arbitrary-file-read</category><category>nodejs</category><category>library</category><category>ssti-adjacent</category></item><item><title>HAXcms Node.js Private Key Disclosure via Broken HMAC (CVE-2026-46395)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-46395-haxcms-hmac-key-leak/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-46395-haxcms-hmac-key-leak/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-46395. Status: PoC. Affects: HAXcms Node.js backend (elmsln/HAXcms, haxcms-nodejs) — src/lib/HAXCMS.js. Tags: haxcms, nodejs, hmac, jwt-forgery, cwe-321, cwe-200, key-disclosure, cms.</description><category>web</category><category>Critical</category><category>haxcms</category><category>nodejs</category><category>hmac</category><category>jwt-forgery</category><category>cwe-321</category><category>cwe-200</category><category>key-disclosure</category><category>cms</category></item><item><title>Handlebars AST Injection Remote Code Execution — CVE-2026-33937</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33937-handlebars-ast-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33937-handlebars-ast-rce/</guid><description>Critical severity — web · CVE-2026-33937. Status: PoC. Affects: Handlebars (Node.js templating engine). Tags: handlebars, rce, template-injection, ast-injection, nodejs, express, javascript-compiler, code-generation.</description><category>web</category><category>Critical</category><category>handlebars</category><category>rce</category><category>template-injection</category><category>ast-injection</category><category>nodejs</category><category>express</category><category>javascript-compiler</category><category>code-generation</category></item><item><title>Ghost CMS Theme JSONPath Remote Code Execution — CVE-2026-29053</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-29053-ghost-cms-jsonpath-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-29053-ghost-cms-jsonpath-rce/</guid><description>High severity — web · CVE-2026-29053 (GHSA-cgc2-rcrh-qr5x). Status: PoC. Affects: Ghost CMS. Tags: ghost-cms, rce, jsonpath, static-eval, handlebars, theme-upload, prototype-pollution, nodejs.</description><category>web</category><category>High</category><category>ghost-cms</category><category>rce</category><category>jsonpath</category><category>static-eval</category><category>handlebars</category><category>theme-upload</category><category>prototype-pollution</category><category>nodejs</category></item><item><title>exiftool-vendored.js Argument Injection via Newline-Delimited Tag Names (CVE-2026-43893)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-43893-exiftool-vendored-arg-injection-file-write/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-43893-exiftool-vendored-arg-injection-file-write/</guid><description>High severity (CVSS 8.2) — misc · CVE-2026-43893 / GHSA-cw26-7653-2rp5. Status: PoC. Affects: exiftool-vendored (npm package, Node.js wrapper around Phil Harvey's ExifTool). Tags: exiftool, exiftool-vendored, argument-injection, arbitrary-file-write, arbitrary-file-read, nodejs, cli-wrapper, newline-injection.</description><category>misc</category><category>High</category><category>exiftool</category><category>exiftool-vendored</category><category>argument-injection</category><category>arbitrary-file-write</category><category>arbitrary-file-read</category><category>nodejs</category><category>cli-wrapper</category><category>newline-injection</category></item><item><title>DbGate `loadReader` `functionName` Injection RCE (CVE-2026-48017)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-48017-dbgate-loadreader-functionname-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-48017-dbgate-loadreader-functionname-rce/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-48017 / GHSA-hv83-ggc4-v385. Status: PoC. Affects: DbGate (dbgate-api), a web-based database management GUI. Tags: dbgate, nodejs, code-injection, rce, cwe-94, authenticated, database-gui.</description><category>web</category><category>High</category><category>dbgate</category><category>nodejs</category><category>code-injection</category><category>rce</category><category>cwe-94</category><category>authenticated</category><category>database-gui</category></item><item><title>AdonisJS bodyparser Path Traversal to Arbitrary File Write (CVE-2026-21440)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-21440-adonisjs-bodyparser-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-21440-adonisjs-bodyparser-path-traversal/</guid><description>Critical severity (CVSS 9.2) — web · CVE-2026-21440 (GHSA-gvq6-hvvp-h34h). Status: Weaponized. Affects: @adonisjs/bodyparser (AdonisJS multipart file-upload handling). Tags: adonisjs, nodejs, path-traversal, arbitrary-file-write, cwe-22, file-upload, rce, bodyparser.</description><category>web</category><category>Critical</category><category>adonisjs</category><category>nodejs</category><category>path-traversal</category><category>arbitrary-file-write</category><category>cwe-22</category><category>file-upload</category><category>rce</category><category>bodyparser</category></item><item><title>NodeBB ActivityPub attributedTo Local UID Spoof</title><link>https://poc.intelseclab.com/pocs/web/2026-07-03_nodebb-activitypub-uid-spoof/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-03_nodebb-activitypub-uid-spoof/</guid><description>High severity — web · None assigned as of 2026-07-03. Status: PoC. Affects: NodeBB — ActivityPub server-to-server inbox. Tags: nodebb, activitypub, federation, authentication-bypass, spoofing, uid-forgery, forum-software, nodejs.</description><category>web</category><category>High</category><category>nodebb</category><category>activitypub</category><category>federation</category><category>authentication-bypass</category><category>spoofing</category><category>uid-forgery</category><category>forum-software</category><category>nodejs</category></item></channel></rss>