PT-2026-52082 · Mastodon · Mastodon

·

CVE-2026-50128

·

Published

2026-06-23

·

Updated

2026-07-06

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mastodon versions 4.3.0 through 4.5.10 Mastodon versions 4.4.0 through 4.4.17
Description Mastodon is a free, open-source social network server based on ActivityPub. A flaw in the definition of the attributionDomains JSON-LD term makes Linked Data Signatures on the toot:attributionDomains property ineffective. This allows an attacker to arbitrarily modify the attributionDomains value of a legitimately signed Update activity and bypass signature verification, potentially leading to false attribution claims.
Recommendations Update to version 4.5.11. Update to version 4.4.18.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MASTODON-2026-50128
CVE-2026-50128
GHSA-PWX3-QCGW-VH7H
GHSA-RWCW-VQ68-G34P

Affected Products

Mastodon