PT-2025-42913 · Mastodon · Mastodon

Published

2025-10-21

·

Updated

2025-12-12

·

CVE-2025-62605

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mastodon versions prior to 4.4.8 Mastodon versions 4.4.0 through 4.4.7 Mastodon versions prior to 4.5.0-beta.2
Description Mastodon is a free, open-source social network server based on ActivityPub. A flaw exists where an attacker can bypass quote controls in certain versions. The issue stems from how Mastodon internally handles reblogs, treating them as statuses. This allows an attacker to reblog a post, then quote their reblog, effectively previewing a post they were not authorized to quote, circumventing the intended quote controls.
Recommendations Update to Mastodon version 4.4.8 or later. Update to Mastodon version 4.5.0-beta.2 or later.

Exploit

Fix

Improper Check for Exceptional Conditions

Weakness Enumeration

Related Identifiers

BIT-MASTODON-2025-62605
CVE-2025-62605
GHSA-8H43-RCQJ-WPC6

Affected Products

Mastodon