๐Ÿ” CVE Alert

CVE-2026-54461

MEDIUM 6.5

Habitica: Regex Injection / ReDoS in Member Search

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Habitica is a habit tracker application that treats goals like a role-playing game. From 4.172.1 until 5.48.2, a query parameter on Habitica's /api/v3/groups/:groupId/members route is not sanitized before being interpreted as a regular expression. An authenticated caller can supply a computationally expensive regular expression that degrades application performance or halts Node.js processes. This issue is fixed in version 5.48.2.

CWE CWE-1333
Vendor habitrpg
Product habitica
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for habitrpg habitica

Be the first to know when new medium vulnerabilities affecting habitrpg habitica are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

HabitRPG / habitica
>= 4.172.1, < 5.48.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/HabitRPG/habitica/security/advisories/GHSA-x772-22c9-gq58 github.com: https://github.com/HabitRPG/habitica/commit/7b7dc255dff1564935675399ff168e8a91b8afca github.com: https://github.com/HabitRPG/habitica/releases/tag/v5.48.2