Moderation Opportunity Exploit in Lemmy Platform
CVE-2026-54742
What is CVE-2026-54742?
Lemmy is a federated link aggregator and forum that suffers from a vulnerability allowing community moderators to improperly feature or unfeature posts owned by other communities. This issue arises from the lack of verification in community moderation actions, enabling unauthorized alterations to featured posts. Specifically, after a verification process, the system fails to confirm that the intended post belongs to the same community, allowing for exploitation of featured feeds and the manipulation of curated content by moderators. This vulnerability has been addressed in the updates, ensuring that community integrity and content curation are upheld.
Affected Version(s)
lemmy < 0.19.19 < 0.19.19
lemmy >= 1.0.0-alpha.0, < 1.0.0-alpha.20 < 1.0.0-alpha.0, 1.0.0-alpha.20
