NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files to arbitrary system locations through the emoji upload API. Attackers with admin access can craft file upload requests with directory traversal to overwrite system files by manipulating the file path parameter.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 22 Jan 2026 02:45:00 +0900

Type Values Removed Values Added
Description NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files to arbitrary system locations through the emoji upload API. Attackers with admin access can craft file upload requests with directory traversal to overwrite system files by manipulating the file path parameter.
Title NodeBB Plugin Emoji 3.2.1 - Arbitrary File Write
Weaknesses CWE-73
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-01-21T17:27:31.014Z

Reserved: 2025-12-31T02:09:17.953Z

Link: CVE-2021-47746

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-21T18:16:02.687

Modified: 2026-01-21T18:16:02.687

Link: CVE-2021-47746

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses