CVE 4.3 MEDIUM

Mastodon quotes control can be bypassed_CVE-2025-62605

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Description

Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon version 4.4, support for verifiable quote posts with quote controls was added, but it is possible for an attacker to bypass these controls in Mastodon versions prior to 4.4.8 and 4.5.0-beta.2. Mastodon internally treats reblogs as statuses. Since they were not special-treated, an attacker could reblog any post, then quote their reblog, technically quoting themselves, but having the quote feature a preview of the post they did not get authorization for with all of the affordances that would be otherwise denied by the quote controls. This issue has been patched in versions 4.4.8 and 4.5.0-beta.2.

Basic Information

ID CVE-2025-62605
Source GitHub_M
Published Oct 21, 2025 at 16:46
Modified Oct 21, 2025 at 18:00

Affected Product

Vendor mastodon
Product mastodon
Version >= 4.4.0-beta.1, < 4.4.8
Affected Versions mastodon mastodon >= 4.4.0-beta.1, < 4.4.8
mastodon mastodon = 4.5.0-beta.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.