CVE-2026-54461
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Summary
Habitica is a habit tracker application that treats goals like a role-playing game. From 4.172.1 until 5.48.2, a query parameter on Habitica's /api/v3/groups/:groupId/members route is not sanitized before being interpreted as a regular expression. An authenticated caller can supply a computationally expensive regular expression that degrades application performance or halts Node.js processes. This issue is fixed in version 5.48.2.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HabitRPG | habitica | >= 4.172.1, < 5.48.2 | affected |
Weaknesses
- CWE-1333: CWE-1333: Inefficient Regular Expression Complexity
References
- https://github.com/HabitRPG/habitica/security/advisories/GHSA-x772-22c9-gq58
- https://github.com/HabitRPG/habitica/commit/7b7dc255dff1564935675399ff168e8a91b8afca
- https://github.com/HabitRPG/habitica/releases/tag/v5.48.2
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.