{"id":"CVE-2025-50979","details":"NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not properly sanitized, allowing unauthenticated, remote attackers to inject boolean-based blind and PostgreSQL error-based payloads.","aliases":["GHSA-rfh2-8vxq-jqr8"],"modified":"2026-08-12T03:51:16.690394832Z","published":"2025-08-27T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/50xxx/CVE-2025-50979.json"},"references":[{"type":"WEB","url":"https://github.com/4rdr/proofs/blob/main/info/NodeBB-v4.3.0.-SQL-Injection-via-search-parameter.md"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/50xxx/CVE-2025-50979.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-50979"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nodebb/nodebb","events":[{"introduced":"7b43b1b80e7bc96b21860349cf17603a226b20f2"},{"last_affected":"7b43b1b80e7bc96b21860349cf17603a226b20f2"}],"database_specific":{"cpe":"cpe:2.3:a:nodebb:nodebb:4.3.0:-:*:*:*:*:*:*","extracted_events":[{"introduced":"4.3.0-NA"},{"last_affected":"4.3.0-NA"}],"source":"CPE_STRING"}}],"versions":["4.3.0-NA","v4.3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-50979.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"}]}