CVE-2025-30741 – Pixelfed Fediverse Server Private Account Information Disclosure

The following table lists the changes that have been made to the
CVE-2025-30741 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Mar. 25, 2025

    Action Type Old Value New Value
    Added Description Pixelfed before 0.12.5 allows anyone to follow private accounts and see private posts on other Fediverse servers. This affects users elsewhere in the Fediverse, if they otherwise have any followers from a Pixelfed instance.
    Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
    Added CWE CWE-863
    Added Reference https://fokus.cool/2025/03/25/pixelfed-vulnerability.html
    Added Reference https://github.com/pixelfed/pixelfed/releases/tag/v0.12.5
    Added Reference https://mastodon.social/@pixelfed/114215925957179498
    Added Reference https://news.ycombinator.com/item?id=43474425
Share the Post:

Related Posts