CVE-2025-62175
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-13

Last updated on: 2025-10-20

Assigner: GitHub, Inc.

Description
Mastodon is a free, open-source social network server based on ActivityPub. In versions before 4.4.6, 4.3.14, and 4.2.27, disabling or suspending a user account does not disconnect the account from the streaming API. This allows disabled or suspended accounts to continue receiving real-time updates through existing streaming connections and to establish new streaming connections, even though they cannot interact with other API endpoints. This undermines moderation actions, as administrators expect disabled or suspended accounts to be fully disconnected from the service. This issue has been patched in versions 4.4.6, 4.3.14, and 4.2.27. No known workarounds exist.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-13
Last Modified
2025-10-20
Generated
2026-06-16
AI Q&A
2025-10-14
EPSS Evaluated
2026-06-14
NVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
joinmastodon mastodon to 4.2.27 (exc)
joinmastodon mastodon From 4.3.0 (inc) to 4.3.14 (exc)
joinmastodon mastodon From 4.4.0 (inc) to 4.4.6 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-273 The product attempts to drop privileges but does not check or incorrectly checks to see if the drop succeeded.
CWE-274 The product does not handle or incorrectly handles when it has insufficient privileges to perform an operation, leading to resultant weaknesses.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability in Mastodon versions before 4.4.6, 4.3.14, and 4.2.27 allows disabled or suspended user accounts to remain connected to the streaming API. Even though these accounts cannot interact with other API endpoints, they can still receive real-time updates and establish new streaming connections. This behavior undermines moderation efforts because administrators expect disabled or suspended accounts to be fully disconnected from the service.

Impact Analysis

The vulnerability can impact you by allowing disabled or suspended user accounts to continue receiving real-time updates and maintain streaming connections despite being restricted from other interactions. This undermines moderation controls and could allow unwanted or problematic users to bypass intended restrictions, potentially affecting the integrity and management of the social network.

Mitigation Strategies

Upgrade Mastodon to version 4.4.6, 4.3.14, or 4.2.27 or later, as these versions contain the patch that fixes the issue. No known workarounds exist.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-62175. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart