
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-50128 is a spoofing vulnerability in Mastodon, the open-source federated social network server, that allows unauthenticated attackers to bypass Linked Data Signature verification and falsely attribute web content to arbitrary users. The flaw affects Mastodon versions 4.3.0 through 4.4.17 and 4.5.0-beta.1 through 4.5.10, and was disclosed on June 24, 2026. Fixed versions are 4.4.18 and 4.5.11. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory).
The root cause is an improper definition of the attributionDomains JSON-LD term within Mastodon's ActivityPub implementation, classified as CWE-354 (Improper Validation of Integrity Check Value). Mastodon v4.3.0 introduced a feature allowing websites to credit article authors via the toot:attributionDomains property; however, due to the erroneous JSON-LD context definition, Linked Data Signatures do not cover this property effectively. As a result, an attacker can intercept a legitimately signed Update activity in transit and arbitrarily modify the attributionDomains value without invalidating the cryptographic signature, bypassing Mastodon's signature verification entirely (GitHub Advisory).
Successful exploitation allows an attacker to modify a valid Update activity for a target user's profile and set an arbitrary attributionDomains value, causing remote Mastodon servers to falsely attribute any chosen webpage to the target user. This is a spoofing/integrity impact with no confidentiality or availability consequences. The attack can be used to damage the reputation of targeted users by associating them with content they did not author or endorse (GitHub Advisory).
Update activities broadcast by the target's Mastodon server (e.g., via a malicious or compromised federated server).toot:attributionDomains property within the intercepted Update activity JSON-LD payload to point to an arbitrary domain of your choosing.Update activity to other Mastodon servers. Because the Linked Data Signature does not effectively cover the attributionDomains property, the signature remains valid and the receiving servers accept the tampered data.Update activities in ActivityPub federation logs where the attributionDomains value does not match the domain previously associated with the target user profile.Update activities with unusual toot:attributionDomains values for established user accounts.Update activity.Mastodon has released patched versions 4.4.18 and 4.5.11 that correct the erroneous JSON-LD definition of attributionDomains, making Linked Data Signatures effective for this property. Server administrators should upgrade to one of these versions as soon as possible. No configuration-based workaround is available; upgrading is the only remediation (GitHub Advisory).
The vulnerability was reported by researcher tesaguri and the advisory was published by Mastodon maintainer renchap on June 3, 2026, with the CVE assigned on June 24, 2026. No significant broader media coverage or notable community commentary beyond the GitHub security advisory has been identified at this time (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."