PT-2026-52082 · Mastodon · Mastodon
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Mastodon versions 4.3.0 through 4.5.10
Mastodon versions 4.4.0 through 4.4.17
Description
Mastodon is a free, open-source social network server based on ActivityPub. A flaw in the definition of the
attributionDomains JSON-LD term makes Linked Data Signatures on the toot:attributionDomains property ineffective. This allows an attacker to arbitrarily modify the attributionDomains value of a legitimately signed Update activity and bypass signature verification, potentially leading to false attribution claims.Recommendations
Update to version 4.5.11.
Update to version 4.4.18.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mastodon