Habitica is a habit tracker application that treats goals like a role-playing game. From 4.172.1 until 5.48.2, a query parameter on Habitica's /api/v3/groups/:groupId/members route is not sanitized before being interpreted as a regular expression. An authenticated caller can supply a computationally expensive regular expression that degrades application performance or halts Node.js processes. This issue is fixed in version 5.48.2.
Multiple reflected XSS vulnerabilities exist in the registration and login forms of habitica, giving the attacker control of the victim’s account when a victim registers or logins with a specially crafted link.
Multiple reflected XSS vulnerabilities exist in the registration and login forms of habitica, giving the attacker control of the victim’s account when a victim registers or logins with a specially crafted link.
In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page.