MEDIUM 6.5 NVD
CVE-2026-54461
Habitica is a habit tracker application that treats goals like a role-playing game. From 4.172.1 until 5.48.2, a query parameter on Habitica's /api/v3/groups/:g
Habitica is a habit tracker application that treats goals like a role-playing game. From 4.172.1 until 5.48.2, a query parameter on Habitica's /api/v3/groups/:groupId/members route is not sanitized before being interpreted as a regular expression. An authenticated caller can supply a computationally expensive regular expression that degrades application performance or halts Node.js processes. This issue is fixed in version 5.48.2.
References
- https://github.com/HabitRPG/habitica/commit/7b7dc255dff1564935675399ff168e8a91b8afca
- https://github.com/HabitRPG/habitica/releases/tag/v5.48.2
- https://github.com/HabitRPG/habitica/security/advisories/GHSA-x772-22c9-gq58
This medium severity vulnerability with a CVSS score of 6.5 was published on 2026-09-24 via NVD.
vulnfeed aggregates 11711 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.