PT-2026-86402 · Pixelfed · Pixelfed
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Pixelfed versions prior to 0.12.10
Description
Authenticated users can access stories restricted to followers due to a failure to validate follower status in the
StoryComposeController react and comment endpoints. By enumerating sequential story IDs and submitting reactions or comments, an attacker can retrieve author information and media URLs of the stories.Recommendations
Update Pixelfed to version 0.12.10 or later.
Restrict access to the
StoryComposeController react and comment endpoints as a temporary mitigation measure.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pixelfed