CVE-2026-50128
Mastodon vulnerability analysis and mitigation

Overview

CVE-2026-50128 is a spoofing vulnerability in Mastodon, the open-source federated social network server, that allows unauthenticated attackers to bypass Linked Data Signature verification and falsely attribute web content to arbitrary users. The flaw affects Mastodon versions 4.3.0 through 4.4.17 and 4.5.0-beta.1 through 4.5.10, and was disclosed on June 24, 2026. Fixed versions are 4.4.18 and 4.5.11. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory).

Technical details

The root cause is an improper definition of the attributionDomains JSON-LD term within Mastodon's ActivityPub implementation, classified as CWE-354 (Improper Validation of Integrity Check Value). Mastodon v4.3.0 introduced a feature allowing websites to credit article authors via the toot:attributionDomains property; however, due to the erroneous JSON-LD context definition, Linked Data Signatures do not cover this property effectively. As a result, an attacker can intercept a legitimately signed Update activity in transit and arbitrarily modify the attributionDomains value without invalidating the cryptographic signature, bypassing Mastodon's signature verification entirely (GitHub Advisory).

Impact

Successful exploitation allows an attacker to modify a valid Update activity for a target user's profile and set an arbitrary attributionDomains value, causing remote Mastodon servers to falsely attribute any chosen webpage to the target user. This is a spoofing/integrity impact with no confidentiality or availability consequences. The attack can be used to damage the reputation of targeted users by associating them with content they did not author or endorse (GitHub Advisory).

Exploitation steps

  1. Identify a target: Select a Mastodon user on a remote server running a vulnerable version (4.3.0–4.4.17 or 4.5.0-beta.1–4.5.10) whose profile attribution you wish to spoof.
  2. Intercept a signed Update activity: Position yourself to observe or intercept ActivityPub Update activities broadcast by the target's Mastodon server (e.g., via a malicious or compromised federated server).
  3. Modify the attributionDomains field: Alter the toot:attributionDomains property within the intercepted Update activity JSON-LD payload to point to an arbitrary domain of your choosing.
  4. Relay the tampered activity: Forward the modified Update activity to other Mastodon servers. Because the Linked Data Signature does not effectively cover the attributionDomains property, the signature remains valid and the receiving servers accept the tampered data.
  5. Achieve false attribution: Remote Mastodon instances now display the attacker-chosen domain as attributed to the target user, associating the victim with content they did not author (GitHub Advisory).

Indicators of compromise

  • Logs: Unexpected or anomalous Update activities in ActivityPub federation logs where the attributionDomains value does not match the domain previously associated with the target user profile.
  • Network: Incoming federation requests from unknown or suspicious Mastodon instances delivering Update activities with unusual toot:attributionDomains values for established user accounts.
  • Application: User profile pages on remote servers displaying attribution to domains not controlled by or associated with the target user, particularly following receipt of an Update activity.

Mitigation and workarounds

Mastodon has released patched versions 4.4.18 and 4.5.11 that correct the erroneous JSON-LD definition of attributionDomains, making Linked Data Signatures effective for this property. Server administrators should upgrade to one of these versions as soon as possible. No configuration-based workaround is available; upgrading is the only remediation (GitHub Advisory).

Community reactions

The vulnerability was reported by researcher tesaguri and the advisory was published by Mastodon maintainer renchap on June 3, 2026, with the CVE assigned on June 24, 2026. No significant broader media coverage or notable community commentary beyond the GitHub security advisory has been identified at this time (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Mastodon vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47389HIGH8.6
  • Mastodon logoMastodon
  • cpe:2.3:a:joinmastodon:mastodon
NoYesJun 24, 2026
CVE-2026-50129HIGH7.5
  • Mastodon logoMastodon
  • cpe:2.3:a:joinmastodon:mastodon
NoYesJun 24, 2026
CVE-2026-48028MEDIUM6.5
  • Mastodon logoMastodon
  • cpe:2.3:a:joinmastodon:mastodon
NoYesJun 24, 2026
CVE-2026-50128MEDIUM5.3
  • Mastodon logoMastodon
  • cpe:2.3:a:joinmastodon:mastodon
NoYesJun 24, 2026
CVE-2026-46349MEDIUM5.3
  • Mastodon logoMastodon
  • cpe:2.3:a:joinmastodon:mastodon
NoYesJun 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management