Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only stories. Attackers can enumerate sequential story IDs and submit reactions or comments to retrieve story media URLs and author information without following the account.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-05 11:16
Updated : 2026-09-08 18:21
NVD link : CVE-2026-86178
Mitre link : CVE-2026-86178
CVE.ORG link : CVE-2026-86178
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
