Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A critical Mastodon flaw, CVE-2023-36460, could let an attacker use a crafted media attachment to make a vulnerable server create or overwrite files—including files that could enable denial of service or remote code execution. The Mastodon project disclosed the issue on July 6, 2023, and named 3.5.9, 4.0.5, and 4.1.3 as patched releases. Those are historical branch-specific fixes, not a guide to upgrading every older installation today.

What was the Mastodon vulnerability?

CVE-2023-36460 is an arbitrary-file-creation flaw in Mastodon’s media attachment processing, tracked as GHSA-9928-3cp5-93fm. According to the Mastodon project advisory, carefully crafted media could cause the server to create or overwrite files at locations accessible to the Mastodon process.

The practical risk depends on what that process can access. The project says the flaw could cause denial of service or arbitrary remote code execution. These are potential consequences of the vulnerability; the advisory does not establish that a particular server was compromised.

Which Mastodon versions were affected?

The affected ranges differ by release branch. The NIST National Vulnerability Database (NVD) entry lists the ranges and fixed releases as follows:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Branch Affected versions Fixed release named in the advisory
3.5 3.5.0 to before 3.5.9 3.5.9
4.0 4.0.0 to before 4.0.5 4.0.5
4.1 4.1.0 to before 4.1.3 4.1.3

These are the versions recorded for this 2023 disclosure. An administrator running an older or otherwise unsupported release should consult current official Mastodon release and upgrade documentation to determine a safe upgrade path, rather than assuming one of these historical fixes is a suitable direct target.

How severe was CVE-2023-36460?

The Mastodon advisory rates the issue CVSS 3.1 9.9 out of 10, Critical. NVD records the same score and the CNA vector, rather than an independent CVSS 4.0 assessment. The vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H: network-accessible, low attack complexity, low privileges required, no user interaction, changed scope, and high potential impact to confidentiality, integrity, and availability.

What should Mastodon administrators do?

  1. Check the running Mastodon version. Compare it with the affected ranges above and identify its release branch.
  2. Plan an upgrade using current official guidance. The historical fixes were 3.5.9, 4.0.5, and 4.1.3 for their respective branches; deployments far behind those versions need a supported upgrade plan.
  3. Verify the deployed version after updating. Confirm the instance is running the intended release, rather than relying only on a completed package or deployment operation.
  4. Assess possible exposure separately from patch status. The advisory establishes the vulnerability and its potential impacts, but does not confirm a campaign or determine whether any named instance was exploited.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How was the flaw discovered?

Mastodon says Cure53 found the issue during a security audit performed at Mozilla’s request. The project published its advisory on July 6, 2023. A July 10, 2023 SecurityWeek report described it as the most important of five Mastodon fixes reported at the time and relayed a warning about possible widespread exploitation. That warning is not evidence that exploitation in the wild was confirmed.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.