#VU126980 Input validation error in Mastodon
Published: February 27, 2025 / Updated: April 23, 2026
Mastodon
Mastodon
Description
The vulnerability allows a remote attacker to conduct phishing attacks through top-level navigation.
The vulnerability exists due to improper input validation in the OEmbed HTML sanitization configuration when processing OEmbed embeds. A remote attacker can supply a crafted OEmbed containing an embed tag to conduct phishing attacks through top-level navigation.
Exploitation is only possible if the deployment environment is severely misconfigured.