Executive brief
Fedify is a library for building federated social networks using the ActivityPub protocol. An authentication bypass vulnerability allows attackers to impersonate any user by sending forged messages to a Fedify-based social network instance. Attackers can create fake posts, follow/unfollow accounts, and boost content as any legitimate user, completely undermining trust in the federated network.
Technical details
The vulnerability is an improper authentication flaw (CWE-287, CWE-863) in the handleInboxInternal function of fedify/federation/handler.ts. The root cause is incorrect order of operations: activities are routed and processed (line 1712) before HTTP signature authentication is validated (line 1730). An attacker can craft an ActivityPub activity claiming to be from any victim actor, sign the HTTP request with their own key, and send it to a Fedify inbox. The activity is processed and queued immediately; the authentication check occurs only after processing, returning a 401 response when it fails—but the damage is already done. No authentication or special privileges are required to exploit this; it affects all Fedify instances up to version 1.8.4. Patches are available: 1.3.20, 1.4.13, 1.5.5, 1.6.8, 1.7.9, and 1.8.5.
Affected products
- Fedify fedify all versions prior to 1.3.20, 1.4.13, 1.5.5, 1.6.8, 1.7.9, 1.8.5
Timeline
- 2025-08-08: disclosed: Vulnerability published
- 2025-08-09: advisory: NVD published CVE-2025-54888
- 2025-08-08: patched: Fixed versions released across multiple branches