


Perceptive Security
SOC/SIEM Consultancy

Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1, any authenticated user can…
Published:
20 April 2026 at 22:00:00
Alert date:
21 April 2026 at 07:08:02
Source:
nvd.nist.gov
Web Technologies, Cloud & Virtualization
A critical vulnerability in Neko, a self-hosted virtual browser running in Docker, allows any authenticated user to gain full administrative control. The vulnerability affects versions 3.0.0-3.0.10 and 3.1.0-3.1.1, enabling complete instance compromise including member management, room settings, broadcast control, and session termination. Patches are available in v3.0.11 and v3.1.2. Temporary mitigations include restricting access to trusted users, using strong passwords, implementing reverse proxy authentication, and monitoring for suspicious privilege changes. The vulnerability appears to be related to the /api/profile endpoint and requires immediate patching for full resolution.
Technical details
Mitigation steps:
Affected products:
Neko
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-39386
https://github.com/m1k1o/neko/releases/tag/v3.0.11
https://github.com/m1k1o/neko/releases/tag/v3.1.2
https://github.com/m1k1o/neko/security/advisories/GHSA-2gw9-c2r2-f5qf
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
