Mastodon - Open Redirect
CVE-2026-33868
Verified
Description
Mastodon version < 4.5.8, < 4.4.15, < 4.3.21 is vulnerable to unauthenticated Open Redirect vulnerability (CWE-601) exists in the /web/* route due to improper handling of URL-encoded path segments.
Severity
Medium
CVSS Score
4.3
Exploit Probability
1%
Affected Product
mastodon
Published Date
March 25, 2026
Template Author
theamanrawat
CVE-2026-33868.yaml
4.3Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVE ID:
cve-2026-33868
CWE ID:
cwe-601
Remediation Steps
Update Mastodon to versions 4.5.8, 4.4.15, 4.3.21.