Improper Authentication in Mastodon - CVE-2024-25618
Published: February 14, 2024 / Updated: April 23, 2026
Mastodon
Mastodon
Description
The vulnerability allows a remote user to take over another user's account.
The vulnerability exists due to improper authentication in external authentication account linking when matching first-time logins to existing local users by e-mail address. A remote user can change the e-mail address on an external identity provider account and log in through the provider to take over another user's account.
Exploitation requires the external authentication provider to allow e-mail address changes or multiple authentication providers to be configured.