Executive brief
NodeBB's password reset functionality uses a mathematically weak random number generator to create reset tokens, allowing attackers to guess valid reset codes and take over user accounts without their knowledge. An attacker only needs to know the target's email address, which may be publicly visible or guessable. This affects all NodeBB installations and enables full account compromise.
Technical details
The vulnerability exists in the `utils.generateUUID` helper function used by NodeBB's password reset mechanism. The function relies on JavaScript's `Math.random()` for generating reset codes, which is not cryptographically secure and its output is predictable. An attacker can use multiple password reset requests combined with brute-force or prediction techniques to calculate valid reset tokens for target accounts. No prior authentication or user interaction is required; the attacker only needs to know or guess the target's email address. Patches are available in versions 1.19.8 and 2.0.1, which replace the weak PRNG with a cryptographically secure random number generator.
Affected products
- NodeBB NodeBB all versions up to and including 1.19.7 and 2.0.0
Timeline
- 2022-08-24: disclosed
- 2022-08-30: patched
- 2022-08-30: advisory