CVE-2025-32946 – Mastodon Playlist Hijacking Vulnerability

The following table lists the changes that have been made to the
CVE-2025-32946 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Apr. 15, 2025

    Action Type Old Value New Value
    Added Description This vulnerability allows any attacker to add playlists to a different user’s channel using the ActivityPub protocol. The vulnerable code sets the owner of the new playlist to be the user who performed the request, and then sets the associated channel to the channel ID supplied by the request, without checking if it belongs to the user.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
    Added CWE CWE-282
    Added Reference https://github.com/Chocobozzz/PeerTube/releases/tag/v7.1.1
    Added Reference https://research.jfrog.com/vulnerabilities/peertube-arbitrary-playlist-creation-activitypub/
Share the Post:

Related Posts