Junglewise Threat Intelligence

CVE-2026-50128: Mastodon signature verification bypass in attributionDomains spoofing

CVE-2026-50128 · Severity: medium · CVSS 5.3 · Published 2026-06-24

Technologies: Mastodon. Vendors: Mastodon.

Executive brief

Mastodon is an open-source social networking platform. A flaw in how the software verifies author credits allows an attacker to falsely link a user's profile to unauthorized websites. This could be used to damage a user's reputation by making it appear as though they authored content on malicious or inappropriate websites.

Technical details

A vulnerability exists in Mastodon's implementation of the 'attributionDomains' JSON-LD term. Due to a definition error, Linked Data Signatures on the 'toot:attributionDomains' property are ineffective. A remote, unauthenticated attacker can intercept and modify a legitimately signed 'Update' activity to change the attribution domains. Because the signature verification is bypassed for this specific property, remote Mastodon servers will accept the modified data, allowing for false attribution of web content to a specific user profile. The issue is resolved in versions 4.4.18 and 4.5.11.

Affected products

  • Mastodon Mastodon >= 4.3.0, < 4.4.18; >= 4.5.0, < 4.5.11

Timeline

  • 2026-06-03: advisory: GitHub Security Advisory published
  • 2026-06-24: disclosed: NVD publication date

References

Related threats