Executive brief
NamelessMC is a website software suite used to manage Minecraft server communities and forums. A security flaw in the forum module allows users to view and interact with reactions on private forum topics they are not authorized to see. This means a user who should only be able to see their own posts could potentially see who reacted to other users' private discussions or add their own reactions to those posts.
Technical details
A missing authorization vulnerability (CWE-862) exists in NamelessMC version 2.2.4 within the `modules/Forum/classes/ForumPostReactionContext.php` component. While the software verifies that a user has general forum access, it fails to check the `view_other_topics` permission when processing reaction queries. An authenticated attacker with low-level privileges can exploit this by sending direct requests to the `/queries/reactions` endpoint. This allows the attacker to read reaction details and add new reactions to posts in topics they are otherwise restricted from viewing. The issue is resolved in version 2.2.5 by enforcing topic visibility checks within the reaction validation logic.
Affected products
- NamelessMC NamelessMC 2.2.4
Timeline
- 2026-05-31: advisory: GitHub Security Advisory GHSA-wcrf-5gcp-pf64 published
- 2026-06-02: disclosed: CVE-2026-35443 published to NVD
- 2026-06-02: patched: Version 2.2.5 released to address the issue