logo

Mastodon Vulnerability Allows Hackers to Hijack Any Decentralized Account

ID: 6043c12d-c348-52a2-b946-fadb07e40f6a

STIX ID: report--6043c12d-c348-52a2-b946-fadb07e40f6a

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-02-03

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Mastodon disclosed a critical origin-validation vulnerability (CVE-2024-23832, severity 9.4) that can allow attackers to impersonate and take over any remote account; many pre-3.5.17 and pre-4.x patch versions are affected. The maintainers credited a security researcher, warned administrators to update instances, and withheld further technical details until a scheduled disclosure date to reduce the risk of easy exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.