
CVE-2026-44224 Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbitrary groups array and applies it directly to … https://www.cve.org/CVERecord?id=CVE-2026-44224
Post summary
The text notes a flaw in Wiki.js versions prior to 2.5.313 where an arbitrary groups array can be supplied to the users.update GraphQL mutation, but lacks additional details such as PoC, exploit, patch, or active exploitation evidence.
