CVE 8.7 HIGH

@fedify/fedify: Improper Authentication and Incorrect Authorization_CVE-2025-54888

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Description

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. In versions below 1.3.20, 1.4.0-dev.585 through 1.4.12, 1.5.0-dev.636 through 1.5.4, 1.6.0-dev.754 through 1.6.7, 1.7.0-pr.251.885 through 1.7.8 and 1.8.0-dev.909 through 1.8.4, an authentication bypass vulnerability allows any unauthenticated attacker to impersonate any ActivityPub actor by sending forged activities signed with their own keys. Activities are processed before verifying the signing key belongs to the claimed actor, enabling complete actor impersonation across all Fedify instances. This is fixed in versions 1.3.20, 1.4.13, 1.5.5, 1.6.8, 1.7.9 and 1.8.5.

Basic Information

ID CVE-2025-54888
Source GitHub_M
Published Aug 9, 2025 at 01:31

Affected Product

Vendor fedify-dev
Product fedify
Version < 1.3.20
Affected Versions fedify-dev fedify < 1.3.20
fedify-dev fedify >= 1.4.0-dev.585, < 1.4.13
fedify-dev fedify >= 1.5.0-dev.636, < 1.5.5
fedify-dev fedify >= 1.6.0-dev.754, < 1.6.8
fedify-dev fedify >= 1.7.0-pr.251.885, < 1.7.9
fedify-dev fedify >= 1.8.0-dev.909, < 1.8.5

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.