PT-2026-28106 · Mastodon · Mastodon
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Mastodon versions prior to 4.5.8
Mastodon versions prior to 4.4.15
Mastodon versions prior to 4.3.21
Description
Mastodon, a free and open-source social network server based on ActivityPub, contains an unauthenticated Open Redirect issue in the
/web/* route. This is due to improper handling of URL-encoded path segments. An attacker can create a specially encoded URL that redirects users to an arbitrary external domain, potentially enabling phishing attacks and OAuth credential theft. The issue arises because URL-encoded slashes (%2F) bypass Rails path normalization and are interpreted as host-relative redirects.Recommendations
Update Mastodon to version 4.5.8 or later.
Update Mastodon to version 4.4.15 or later.
Update Mastodon to version 4.3.21 or later.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mastodon