CVE-2026-54461

MEDIUM Status: Received

CVSS Scores

CVSS v3.x Base Score
6.5
MEDIUM

Description

Habitica is a habit tracker application that treats goals like a role-playing game. From 4.172.1 until 5.48.2, a query parameter on Habitica's /api/v3/groups/:groupId/members route is not sanitized before being interpreted as a regular expression. An authenticated caller can supply a computationally expensive regular expression that degrades application performance or halts Node.js processes. This issue is fixed in version 5.48.2.

Published
September 24, 2026 6:17 PM
Last Modified
September 24, 2026 6:17 PM
Source
[email protected]

Weaknesses (CWE)

CWE-1333

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.