NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files to arbitrary system locations through the emoji upload API. Attackers with admin access can craft file upload requests with directory traversal to overwrite system files by manipulating the file path parameter.
Metrics
Affected Vendors & Products
References
History
Fri, 23 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nodebb
Nodebb nodebb |
|
| Vendors & Products |
Nodebb
Nodebb nodebb |
Thu, 22 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 21 Jan 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files to arbitrary system locations through the emoji upload API. Attackers with admin access can craft file upload requests with directory traversal to overwrite system files by manipulating the file path parameter. | |
| Title | NodeBB Plugin Emoji 3.2.1 - Arbitrary File Write | |
| Weaknesses | CWE-73 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-01-21T17:27:31.014Z
Updated: 2026-01-22T16:21:42.322Z
Reserved: 2025-12-31T02:09:17.953Z
Link: CVE-2021-47746
Updated: 2026-01-22T16:21:37.924Z
Status : Received
Published: 2026-01-21T18:16:02.687
Modified: 2026-01-21T18:16:02.687
Link: CVE-2021-47746
No data.