Message Editing Flaw in Lemmy Forum Software Allows Post-Block Harassment
CVE-2026-54741

5.3MEDIUM

Key Information:

Vendor

Lemmynet

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-54741?

A vulnerability in Lemmy, a link aggregator and forum in the fediverse, allows users who have been blocked to modify existing private messages. Despite blocking a sender, the software does not enforce the block when editing messages, permitting a blocked sender to alter the content of messages still visible to the recipient. This flaw poses a risk of post-block harassment, as users may receive updated messages from someone they have intentionally blocked. The issue has been addressed in versions 0.19.19 and 1.0.0-alpha.18.

Affected Version(s)

lemmy < 0.19.19 < 0.19.19

lemmy >= 1.0.0-alpha.0, < 1.0.0-alpha.18 < 1.0.0-alpha.0, 1.0.0-alpha.18

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.