
🚨*CVE* CVE-2026-58593 NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound middleware verifies the HTTP-signature actor a… https://www.cve.org/CVERecord?id=CVE-2026-58593 ----- Traducción: CVE-2026-58593 Nod… http://infoflow.cloud`
Post summary
The tweet announces a NodeBB vulnerability (CVE-2026-58593) that allows unauthenticated actors to claim ownership of inbound ActivityPub objects, but provides no PoC, exploit, patch, or evidence of active exploitation.

