Arbitrary file creation through media attachments on Mastodon

CVE-2023-36460 is a Mastodon vulnerability where you can send a toot which makes a webshell on instances that process said toot.

Edit: it's already fixed, that's why it was disclosed on GitHub.

The security advisory: https://github.com/mastodon/mastodon/security/advisories/GHSA-9928-3cp5-93fm

65 points · 3 comments · view on lemmy.world

3 Comments

alphapuggle@programming.dev · 6 pts · 3y (1 reply)

Not sure if this is related, but I think they pushed an update for it https://mastodon.social/@Mastodon/110667890329356603

edu4rdshl@lemmy.world · 5 pts · 3y

Yes, it's already fixed, that's why it was disclosed on Github. I will edit the post to reflect that.

Lemmesee@lemm.ee · 1 pts · 3y

Woof