Cross-site scripting in Mastodon - #VU126981
Published: April 23, 2026
Mastodon
Detailed vulnerability description
The vulnerability allows a remote attacker to conduct cross-site scripting attacks.
The vulnerability exists due to improper neutralization of input during web page generation in user-facing URLs for remote accounts, posts, and media attachments when handling remote object data. A remote attacker can supply a crafted user-facing URL to conduct cross-site scripting attacks.
Exploitation is limited to third-party clients and servers that strip the Content-Security-Policy header.