Improper Handling of Insufficient Privileges in Mastodon - CVE-2025-62175

 

Improper Handling of Insufficient Privileges in Mastodon - CVE-2025-62175

Published: April 23, 2026


Vulnerability identifier: #VU126985
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-62175
CWE-ID: CWE-274
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper handling of insufficient privileges in the streaming API when processing streaming API connections for disabled or suspended accounts. A remote user can reconnect to the streaming API after the account has been disabled or suspended to disclose sensitive information.

Disabled or suspended accounts may remain connected and continue receiving messages through the streaming API even though they cannot interact with other APIs.


Affected software

Mastodon

How to mitigate CVE-2025-62175

Install security update from vendor's website.

Mastodon - addressed in versions 4.2.27, 4.3.14, 4.4.6

External References

Related Security Bulletins