Damus
silverpill profile picture
silverpill
@silverpill
https://www.openwall.com/lists/oss-security/2026/03/09/7

Misskey and Sharkey, ActivityPub-based social network services (similar to Mastodon), have released updates to patch vulnerabilities Sharkey maintainers describe as "extremely severe".

Details have not been not published yet but "missing permission checks" and "authentication bypass" sound like vulnerabilities that could be prevented by following recommendations from FEP-fe34: Origin-based security model.
1
Phantasm · 1w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqdf0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqvrnptm It's nothing serious or severe. You could see posts you weren't supposed to if you were blocked and probably not a follower. And an HTTP signatures bypass. https://activitypub.software/...