Message Editing Flaw in Lemmy Forum Software Allows Post-Block Harassment
CVE-2026-54741
5.3MEDIUM
What is CVE-2026-54741?
A vulnerability in Lemmy, a link aggregator and forum in the fediverse, allows users who have been blocked to modify existing private messages. Despite blocking a sender, the software does not enforce the block when editing messages, permitting a blocked sender to alter the content of messages still visible to the recipient. This flaw poses a risk of post-block harassment, as users may receive updated messages from someone they have intentionally blocked. The issue has been addressed in versions 0.19.19 and 1.0.0-alpha.18.
Affected Version(s)
lemmy < 0.19.19 < 0.19.19
lemmy >= 1.0.0-alpha.0, < 1.0.0-alpha.18 < 1.0.0-alpha.0, 1.0.0-alpha.18
