PT-2026-95907 · Pixelfed · Pixelfed
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Pixelfed versions prior to 0.12.10
Description
An issue exists in the OAuth Scope Handler component within the
instancePeers() function of the app/Http/Controllers/Api/ApiV1Controller.php file. Remote manipulation of the ID argument can lead to missing authentication.Recommendations
Update to version 0.12.10.
Exploit
Fix
Missing Authentication
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pixelfed