Privacy Flaw in Pixelfed by Pixelfed Corporation
CVE-2025-30741

4.3MEDIUM

Key Information:

Vendor

Pixelfed

Status
Vendor
CVE Published:
25 March 2025

What is CVE-2025-30741?

A significant privacy vulnerability exists in Pixelfed prior to version 0.12.5, where unauthorized users can bypass privacy settings allowing them to follow private accounts and view private posts on other servers within the Fediverse. This flaw compromises user confidentiality and highlights the importance of applying security updates promptly. Users are urged to upgrade to the latest version to secure their accounts against these unauthorized access risks.

Affected Version(s)

Pixelfed 0 < 0.12.5

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.