Mastodon vulnerable to Cross-site Scripting through oEmbed preview cards
CVE-2023-36459
9.3CRITICAL
What is CVE-2023-36459?
The vulnerability in Mastodon allows an attacker to bypass HTML sanitization via specially crafted oEmbed data. This can lead to the inclusion of malicious HTML in oEmbed preview cards, posing serious security risks to users. When users interact with a compromised link, they could unknowingly execute XSS payloads, thereby opening their browsers to various attacks. Secure versions, including 3.5.9, 4.0.5, and 4.1.3, have been patched to mitigate this risk.
Affected Version(s)
mastodon >= 1.3, < 3.5.9 < 1.3, 3.5.9
mastodon >= 4.0.0, < 4.0.5 < 4.0.0, 4.0.5
mastodon >= 4.1.0, < 4.1.3 < 4.1.0, 4.1.3
