GHSA-cxpc-p44g-hxj7MediumCVSS 5.4
Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and...
🔗 CVE IDs covered (1)
📋 Description
Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only stories. Attackers can enumerate sequential story IDs and submit reactions or comments to retrieve story media URLs and author information without following the account.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-86178
- https://github.com/geo-chen/oss/blob/main/Pixelfed.md
- https://github.com/pixelfed/pixelfed
- https://github.com/pixelfed/pixelfed/blob/v0.12.9/app/Http/Controllers/StoryComposeController.php#L487-L501
- https://github.com/pixelfed/pixelfed/blob/v0.12.9/app/Http/Controllers/StoryComposeController.php#L566-L580
- https://github.com/pixelfed/pixelfed/blob/v0.12.9/routes/web-api.php#L154-L155
- https://www.vulncheck.com/advisories/pixelfed-through-0.12.9-unauthorized-story-access-via-api
- https://github.com/advisories/GHSA-cxpc-p44g-hxj7