CVE-2025-30741

Pixelfed before 0.12.5 allows anyone to follow private accounts and see private posts on other Fediverse servers. This affects users elsewhere in the Fediverse, if they otherwise have any followers from a Pixelfed instance.
Configurations

No configuration.

History

No history.

Information

Published : 2025-03-25 21:15

Updated : 2025-03-27 16:45


NVD link : CVE-2025-30741

Mitre link : CVE-2025-30741

CVE.ORG link : CVE-2025-30741


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization