digipres.club is part of the decentralized social network powered by Mastodon.

Administered by:

Server stats:

266
active users

Learn more

Misty

Wow, this Pixelfed bug is *nasty*. Allowed users to access private posts of remote users they're not following so long as another user on the same Pixelfed server legitimately followed that account.

If you're running a Pixelfed server, definitely upgrade immediately now that the vulnerability is publicly known.

fokus.cool/2025/03/25/pixelfed

fokus.cool Pixelfed leaks private posts from other Fediverse instances - fiona fokus