{"id":"CVE-2026-54461","published":"2026-09-24T18:17:13.820","lastModified":"2026-09-28T15:17:18.060","description":"Habitica is a habit tracker application that treats goals like a role-playing game. From 4.172.1 until 5.48.2, a query parameter on Habitica's /api/v3/groups/:groupId/members route is not sanitized before being interpreted as a regular expression. An authenticated caller can supply a computationally expensive regular expression that degrades application performance or halts Node.js processes. This issue is fixed in version 5.48.2.","cvssScore":6.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-1333"],"vendors":[],"products":[],"references":[{"url":"https://github.com/HabitRPG/habitica/commit/7b7dc255dff1564935675399ff168e8a91b8afca","tags":[]},{"url":"https://github.com/HabitRPG/habitica/releases/tag/v5.48.2","tags":[]},{"url":"https://github.com/HabitRPG/habitica/security/advisories/GHSA-x772-22c9-gq58","tags":[]}],"exploitRefs":[{"url":"https://github.com/HabitRPG/habitica/commit/7b7dc255dff1564935675399ff168e8a91b8afca","tags":[]},{"url":"https://github.com/HabitRPG/habitica/releases/tag/v5.48.2","tags":[]},{"url":"https://github.com/HabitRPG/habitica/security/advisories/GHSA-x772-22c9-gq58","tags":[]}],"hasPoc":true,"ai":null}