Input validation error in Mastodon - #VU126980
Published: February 27, 2025 / Updated: April 23, 2026
Mastodon
Detailed vulnerability description
The vulnerability allows a remote attacker to conduct phishing attacks through top-level navigation.
The vulnerability exists due to improper input validation in the OEmbed HTML sanitization configuration when processing OEmbed embeds. A remote attacker can supply a crafted OEmbed containing an embed tag to conduct phishing attacks through top-level navigation.
Exploitation is only possible if the deployment environment is severely misconfigured.