CVE-2025-30741 Information

Description

Pixelfed before 0.12.5 allows anyone to follow private accounts and see private posts on other Fediverse servers. This affects users elsewhere in the Fediverse if they otherwise have any followers from a Pixelfed instance.

Reference

https://fokus.cool/2025/03/25/pixelfed-vulnerability.html https://github.com/pixelfed/pixelfed/releases/tag/v0.12.5 https://mastodon.social/@pixelfed/114215925957179498 https://news.ycombinator.com/item?id=43474425

Share on: