logo

Critical vulnerability in Mastodon is pounced upon by fast-acting admins

ID: 0fb9ea0d-ef47-50e9-83dd-b48491456b66

STIX ID: report--0fb9ea0d-ef47-50e9-83dd-b48491456b66

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-02-02

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Mastodon disclosed a critical remote account-takeover vulnerability (CVE-2024-23832, CVSS 9.4) caused by insufficient origin validation affecting multiple versions (prior to 3.5.17, 4.0.13, 4.1.13, and 4.2.5). The project withheld full technical details until a scheduled disclosure to give administrators time to patch; the decentralised nature of Mastodon means each instance must be updated individually, though many servers patched quickly after the advisory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.