Information disclosure in Mastodon - #VU139922
Published: July 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to incorrect access control validation in user collection access controls when handling requests for collection member information. A remote attacker can access personally identifying information of other local users to disclose sensitive information.
The exposed information includes the last used IP address and current email address of another local user that is currently part of a collection.