CVE-2023-36460
NixOS vulnerability analysis and mitigation

Overview

CVE-2023-36460 is a critical vulnerability in Mastodon, a free and open-source social network server based on ActivityPub. The vulnerability was discovered by Cure53 during an audit requested by Mozilla and affects versions from 3.5.0 up to (but not including) versions 3.5.9, 4.0.5, and 4.1.3. The flaw allows attackers to exploit Mastodon's media processing code to create arbitrary files at any location (GitHub Advisory, NVD).

Technical details

The vulnerability has been assigned a Critical severity rating with a CVSS v3.1 score of 9.9, indicating its high impact potential. The attack vector is Network-based (AV:N), with Low attack complexity (AC:L), requiring Low privileges (PR:L), and No user interaction (UI:N). The scope is Changed (S:C), with High impact on Confidentiality, Integrity, and Availability (C:H/I:H/A:H) (GitHub Advisory).

Impact

The vulnerability enables attackers to create and overwrite any file that Mastodon has access to, potentially leading to Denial of Service and arbitrary Remote Code Execution. If exploited, attackers could potentially bring down the entire Mastodon infrastructure, with hijacked instances potentially sending false alerts to users or coercing them to download malicious applications (Security Online, Hacker News).

Mitigation and workarounds

The vulnerability has been patched in Mastodon versions 3.5.9, 4.0.5, and 4.1.3. Users are strongly advised to upgrade to these patched versions. The update also includes additional security hardening measures, such as new recommended reverse proxy configurations and an updated minimum supported ImageMagick version requirement of 6.9.7-7 (GitHub Release).

Community reactions

The security update received positive reactions from the community, as evidenced by the GitHub release reactions. The release of version 4.1.3 garnered 39 thumbs up, 11 celebration, 9 heart, and 7 rocket reactions from the community, indicating strong support for the security fixes (GitHub Release).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-12819HIGH8.1
  • NixOSNixOS
  • pgbouncer
NoYesDec 03, 2025
CVE-2025-20777MEDIUM6.7
  • NixOSNixOS
  • android
NoNoDec 02, 2025
CVE-2025-65105MEDIUM5.3
  • NixOSNixOS
  • apptainer
NoYesDec 02, 2025
CVE-2025-20789MEDIUM4.4
  • NixOSNixOS
  • android
NoNoDec 02, 2025
CVE-2025-20788MEDIUM4.4
  • NixOSNixOS
  • android
NoNoDec 02, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management