Any authenticated user can immediately obtain full administrative control of the entire Neko instance (member management, room settings, broadcast control, session termination, etc.). This results in a complete compromise of the instance.
The vulnerability has been patched in the following releases:
Users should upgrade to v3.0.11 or later (for the 3.0 branch) or v3.1.2 or later.
If upgrading is not immediately possible, the following mitigations can reduce risk:
/api/profile endpoint if feasibleNote: These are temporary mitigations and do not fully eliminate the vulnerability. Upgrading is strongly recommended.
Neko thanks @blitzkrieg-patch for responsibly disclosing this vulnerability and reaching out directly. This contribution helped strengthen the project, and the whole community benefits from it.
{
"cwe_ids": [
"CWE-20",
"CWE-269",
"CWE-284",
"CWE-639",
"CWE-862"
],
"github_reviewed": true,
"github_reviewed_at": "2026-04-21T17:24:42Z",
"nvd_published_at": "2026-04-21T01:16:06Z",
"severity": "HIGH"
}