CVE & Vulnerabilities · September 22, 2026
A newly disclosed vulnerability in Pixelfed, the decentralized photo-sharing platform, lets remote attackers bypass authentication through its OAuth scope handling and pull instance-peer data without valid credentials. The bug affects installations up through version 0.12.11, and a public exploit for it is already circulating. Site administrators are advised to update to a patched release as soon as possible.
// source: nvd.nist.gov ↗