Medium severity5.4NVD Advisory· Published Jul 6, 2023· Updated Jun 17, 2026
CVE-2023-36462
CVE-2023-36462
Description
Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 2.6.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, an attacker can craft a verified profile link using specific formatting to conceal arbitrary parts of the link, enabling it to appear to link to a different URL altogether. The link is visually misleading, but clicking on it will reveal the actual link. This can still be used for phishing, though, similar to IDN homograph attacks. Versions 3.5.9, 4.0.5, and 4.1.3 contain a patch for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4Patches
Vulnerability mechanics
References
5- github.com/mastodon/mastodon/commit/610731b03dfcadd887078cb0399f4e514aa1931cnvdPatch
- github.com/mastodon/mastodon/security/advisories/GHSA-55j9-c3mp-6fcqnvdVendor Advisory
- github.com/mastodon/mastodon/releases/tag/v3.5.9nvdRelease Notes
- github.com/mastodon/mastodon/releases/tag/v4.0.5nvdRelease Notes
- github.com/mastodon/mastodon/releases/tag/v4.1.3nvdRelease Notes
News mentions
0No linked articles in our index yet.