Home | Notifications | New Note | Local | Federated | Search | Logout

Note Detail


GoToSocial@gotosocial@gts.superseriousbusiness.org (2026-07-06 20:02:53)
Hello sloth aficionados!

This is a security announcement for an issue that was fixed in #GoToSocial releases v0.21.3 and v0.22.0. If you are running an earlier version of GoToSocial please find time to upgrade to one of these releases as soon as possible!

The security vulnerability allows a remote attacker crafting (properly signed) ActivityPub activies to send Create, Update and Announce activities to a GtS instance that persist statuses / boosts as if they were written by a remote victim account. This happens due to our (previously) incorrect handling of multi-valued attributedTo and actor in the effected activities. We are not aware of anybody using this vulnerability in the wild, but it remains possible on all GtS versions v0.21.2 and below.

This was kindly disclosed to us by Lain of the Pleroma project, thank you Lain!

Timeline:

June 23rd, Lain emailed admin@gotosocial.org with details of the issue.
June 24th, a fix was merged.
June 25th, versions v0.21.3 and v0.22.0-rc4 including the fix were released, along with a pre-disclosure warning of the security issue urging users to update.
July 6th, security vulnerability publicly disclosed by this post.
Reply