{"id":"GHSA-2gw9-c2r2-f5qf","summary":"Neko has a Self-service Privilege Escalation for Authenticated Users","details":"### Impact\n\nAny authenticated user can immediately obtain full administrative control of the entire Neko instance (member management, room settings, broadcast control, session termination, etc.). This results in a complete compromise of the instance.\n\n### Patches\n\nThe vulnerability has been patched in the following releases:\n\n- [v3.0.11](https://github.com/m1k1o/neko/releases/tag/v3.0.11) (backport release)\n- [v3.1.2](https://github.com/m1k1o/neko/releases/tag/v3.1.2) (latest stable release)\n\nUsers should upgrade to [v3.0.11](https://github.com/m1k1o/neko/releases/tag/v3.0.11) or later (for the 3.0 branch) or [v3.1.2](https://github.com/m1k1o/neko/releases/tag/v3.1.2) or later.\n\n### Workarounds\n\nIf upgrading is not immediately possible, the following mitigations can reduce risk:\n\n- Restrict access to trusted users only (avoid granting accounts to untrusted parties)\n- Run the instance only when needed; avoid leaving it continuously exposed\n- Disable or restrict access to the `/api/profile` endpoint if feasible\n- Monitor for suspicious privilege changes or unexpected administrative actions\n\nNote: These are temporary mitigations and do not fully eliminate the vulnerability. Upgrading is strongly recommended.\n\n### Credits\nNeko thanks @blitzkrieg-patch for responsibly disclosing this vulnerability and reaching out directly. This contribution helped strengthen the project, and the whole community benefits from it.","aliases":["CVE-2026-39386","GO-2026-4960"],"modified":"2026-06-09T10:52:18Z","published":"2026-04-21T17:24:42Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-04-21T17:24:42Z","nvd_published_at":"2026-04-21T01:16:06Z","cwe_ids":["CWE-20","CWE-269","CWE-284","CWE-639","CWE-862"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/m1k1o/neko/security/advisories/GHSA-2gw9-c2r2-f5qf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39386"},{"type":"WEB","url":"https://github.com/m1k1o/neko/commit/6b561feb9016badea99ae7305091c0ff55e1d114"},{"type":"WEB","url":"https://github.com/m1k1o/neko/commit/c54bcf1ee211e28104a2bb6db59583a39c4a4d6e"},{"type":"PACKAGE","url":"https://github.com/m1k1o/neko"},{"type":"WEB","url":"https://github.com/m1k1o/neko/releases/tag/v3.0.11"},{"type":"WEB","url":"https://github.com/m1k1o/neko/releases/tag/v3.1.2"}],"affected":[{"package":{"name":"github.com/m1k1o/neko/server","ecosystem":"Go","purl":"pkg:golang/github.com/m1k1o/neko/server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.0.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-2gw9-c2r2-f5qf/GHSA-2gw9-c2r2-f5qf.json"}},{"package":{"name":"github.com/m1k1o/neko/server","ecosystem":"Go","purl":"pkg:golang/github.com/m1k1o/neko/server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-20250322225643-212bf8a60756"},{"fixed":"0.0.0-20260406184107-c54bcf1ee211"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-2gw9-c2r2-f5qf/GHSA-2gw9-c2r2-f5qf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}