Junglewise Threat Intelligence

CVE-2026-47777: Mastodon authorization bypass in experimental Collections feature

CVE-2026-47777 · Severity: high · CVSS 7.5 · Published 2026-06-15

Technologies: Mastodon. Vendors: Mastodon.

Executive brief

Mastodon is an open-source decentralized social networking platform. A security flaw in an experimental feature allowed attackers to falsely claim that a user had consented to be featured in a specific group or collection. This could be used to misrepresent a user's affiliations or include their profile in collections against their will, potentially damaging their reputation or privacy.

Technical details

An authorization bypass exists in Mastodon's experimental 'Collections' feature due to insufficient verification of the FeatureAuthorization object. While the system checks that the authorization originates from the correct domain, it fails to verify that the object referenced in the authorization matches the item being added to the Collection. A remote, unauthenticated attacker can exploit this missing condition to forge consent, making it appear as if a remote account has agreed to be featured. This vulnerability only affects servers running nightly or main branch builds with the EXPERIMENTAL_FEATURES environment variable set to include 'collections'. The issue is addressed in version 4.6.0-beta.1 and nightly builds starting from 2026-05-21.

Affected products

  • Mastodon Mastodon nightly builds between 2026-03-10 and 2026-05-21; main branch prior to commit 22203f8

Timeline

  • 2026-05-20: advisory: GitHub Security Advisory published
  • 2026-05-21: patched: Fixed in nightly builds and main branch commit 22203f8
  • 2026-06-15: disclosed: CVE-2026-47777 published to NVD

References

Related threats