Skip to content

Private mention filtering can be bypassed

Low
renchap published GHSA-5fq7-3p3j-9vrf May 30, 2024

Package

No package listed

Affected versions

all

Patched versions

4.2.9, 4.1.17

Description

Summary

Mastodon allows users to ignore or filter private mentions from non-followers, with an exception for replies to private mentions initiated by the user. However, the implementation of that exception was incorrect, allowing attackers to send Private Mentions to people with whom they have no follow relationships.

Impact

This vulnerability allows bypassing some of Mastodon's filtering capabilities, so it can be used for spam or harassment, but the impact is limited as other filtering capabilities such as blocks, mutes, and word filters are unaffected.

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs

Credits