peter bassill · operator
$ cve CVE-2023-36460 JSON

CVE-2023-36460

9.9
CRITICAL · CVSS 3.1 · EPSS 40.1% (pctl 99)

Patch early

EPSS 40.1% — above the 10% action threshold.

Description

Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, attackers using carefully crafted media files can cause Mastodon's media processing code to create arbitrary files at any location. This allows attackers to create and overwrite any file Mastodon has access to, allowing Denial of Service and arbitrary Remote Code Execution. Versions 3.5.9, 4.0.5, and 4.1.3 contain a patch for this issue.

Scoring

CVSS9.9 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS40.11% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploitnone known
Published2023-07-06
Last modified2026-06-17

Affected (1)

VendorProduct
joinmastodonmastodon

References

→ the Explorer  ·  watch your stack  ·  NVD