#VU126974 Improper access control in Mastodon - CVE-2024-37903
Published: July 4, 2024 / Updated: April 23, 2026
Mastodon
Mastodon
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in audience extension handling for existing posts when processing crafted activities. A remote attacker can send specific crafted activities to disclose sensitive information.
Exploitation requires knowledge of the protocol identifier for the target message and control of an account on a Mastodon server that already has legitimate access to that message.