CVE-2026-73038 - NodeBB 4.15.0 Stored XSS via ActivityPub emoji tag.icon.url and tag.name
Brief
CVE ID : CVE-2026-73038
Published : Aug. 13, 2026, 6:41 p. m.
- 23 minutes ago
Description : NodeBB before 4.
- 0 contains a stored cross-site scripting vulnerability in the renderEmoji function that fails to escape tag. icon. url and tag. name attributes. Attackers can deliver malicious ActivityPub Create/Note objects with crafted emoji tags to inject arbitrary HTML and JavaScript into stored post content, executing code in all viewers' browsers.
Severity: 6.1
- MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
