Information disclosure in Mastodon - #VU139922

 

Information disclosure in Mastodon - #VU139922

Published: July 28, 2026


Vulnerability identifier: #VU139922
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to incorrect access control validation in user collection access controls when handling requests for collection member information. A remote attacker can access personally identifying information of other local users to disclose sensitive information.

The exposed information includes the last used IP address and current email address of another local user that is currently part of a collection.


Affected software

Mastodon

Remediation

Install security update from vendor's website.

Mastodon - update to 4.6.4

External References

Related Security Bulletins