CVE-2025-62175
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-13

Last updated on: 2025-10-20

Assigner: GitHub, Inc.

Description
Mastodon is a free, open-source social network server based on ActivityPub. In versions before 4.4.6, 4.3.14, and 4.2.27, disabling or suspending a user account does not disconnect the account from the streaming API. This allows disabled or suspended accounts to continue receiving real-time updates through existing streaming connections and to establish new streaming connections, even though they cannot interact with other API endpoints. This undermines moderation actions, as administrators expect disabled or suspended accounts to be fully disconnected from the service. This issue has been patched in versions 4.4.6, 4.3.14, and 4.2.27. No known workarounds exist.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-13
Last Modified
2025-10-20
Generated
2026-05-07
AI Q&A
2025-10-14
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
joinmastodon mastodon to 4.2.27 (exc)
joinmastodon mastodon From 4.3.0 (inc) to 4.3.14 (exc)
joinmastodon mastodon From 4.4.0 (inc) to 4.4.6 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-274 The product does not handle or incorrectly handles when it has insufficient privileges to perform an operation, leading to resultant weaknesses.
CWE-273 The product attempts to drop privileges but does not check or incorrectly checks to see if the drop succeeded.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability in Mastodon versions before 4.4.6, 4.3.14, and 4.2.27 allows disabled or suspended user accounts to remain connected to the streaming API. Even though these accounts cannot interact with other API endpoints, they can still receive real-time updates and establish new streaming connections. This behavior undermines moderation efforts because administrators expect disabled or suspended accounts to be fully disconnected from the service.


How can this vulnerability impact me? :

The vulnerability can impact you by allowing disabled or suspended user accounts to continue receiving real-time updates and maintain streaming connections despite being restricted from other interactions. This undermines moderation controls and could allow unwanted or problematic users to bypass intended restrictions, potentially affecting the integrity and management of the social network.


What immediate steps should I take to mitigate this vulnerability?

Upgrade Mastodon to version 4.4.6, 4.3.14, or 4.2.27 or later, as these versions contain the patch that fixes the issue. No known workarounds exist.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart