Moderation Opportunity Exploit in Lemmy Platform
CVE-2026-54742

5.1MEDIUM

Key Information:

Vendor

Lemmynet

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-54742?

Lemmy is a federated link aggregator and forum that suffers from a vulnerability allowing community moderators to improperly feature or unfeature posts owned by other communities. This issue arises from the lack of verification in community moderation actions, enabling unauthorized alterations to featured posts. Specifically, after a verification process, the system fails to confirm that the intended post belongs to the same community, allowing for exploitation of featured feeds and the manipulation of curated content by moderators. This vulnerability has been addressed in the updates, ensuring that community integrity and content curation are upheld.

Affected Version(s)

lemmy < 0.19.19 < 0.19.19

lemmy >= 1.0.0-alpha.0, < 1.0.0-alpha.20 < 1.0.0-alpha.0, 1.0.0-alpha.20

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.