Executive brief
Pixelfed, a photo-sharing social platform, contains an authentication bypass vulnerability in its OAuth scope handler. An unauthenticated remote attacker can manipulate the ID parameter to bypass authentication and perform unauthorized actions without proper credentials, potentially leading to unauthorized account modifications.
Technical details
The vulnerability exists in the accountRemoveFollowById function within app/Http/Controllers/Api/ApiV1Controller.php where missing authentication checks allow manipulation of the ID argument to bypass OAuth scope validation. The attack is network-based and requires no authentication, enabling remote exploitation to perform authenticated API operations without valid credentials. A patch has been released that adds proper authentication verification.
Affected products
- Pixelfed Pixelfed up to 0.12.11
Timeline
- 2026-09-20: disclosed
- 2026-09-20: patched: commit 68dca5097305fa0065d029587b2233524636025a