Back to news

NodeBB Forum Flaws Patched; LG Moves to Block Smart TV Proxy Abuse

Two security disclosures this week expose risks hiding in everyday software—forum platforms and living-room televisions alike.

NodeBB Forum Flaws Patched; LG Moves to Block Smart TV Proxy Abuse

What happened

Aikido Security disclosed eight high-severity vulnerabilities in NodeBB, the open-source forum platform, after its AI-assisted penetration testing agents audited the source code in roughly six hours. The flaws—accompanied by working exploit code—could allow attackers to gain administrative access or read private conversations, and every NodeBB release prior to version 4.14.0 is considered vulnerable. NodeBB has addressed all eight issues, with version 4.14.2 representing the current recommended baseline. Separately, LG Electronics USA announced plans to pull smart TV applications from its webOS store that quietly enroll users' televisions as residential proxy nodes, routing third-party internet traffic through household connections without meaningful user awareness.

Why it matters for your business

Organizations running community forums, customer support boards, or internal discussion tools on NodeBB should treat the upgrade to 4.14.2 as an urgent priority—delayed patching leaves admin credentials and user data directly exposed. The LG situation carries a different but equally serious lesson: software supply-chain risk now extends to consumer-grade hardware sitting inside employee homes or corporate break rooms. If a smart TV on a corporate network becomes a residential proxy exit node, it can complicate traffic attribution, introduce compliance headaches, and serve as a vector for further intrusion. Security leaders should audit which networked devices—beyond traditional endpoints—have unvetted app ecosystems capable of silently proxying traffic.

What to watch next

The NodeBB case will likely accelerate adoption conversations around AI-driven code auditing, given that a six-hour automated review surfaced eight high-severity issues that had gone undetected. Watch for other open-source projects to commission similar assessments under public pressure. On the LG front, regulators and consumer-protection bodies in the US and EU may scrutinize whether app-store operators bear liability when third-party titles monetize users' bandwidth without explicit informed consent.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp