CVE-2022-46164 NodeBB is an open source Nodejs based forum software Due to a plain object with a prototype being used in socketio message handling a specially crafted payload can be used to impersonate other users and takeover accounts This vulnerability has been patched in version 261 Users are advised to upgrade Users unable to upgrade may cherry-pick commit 48d143921