CVE-2026-33868 - Vulnerability Analysis
MediumCVSS: 4.3Last Updated: March 27, 2026
Mastodon - Open Redirect
Published: March 27, 2026Updated: March 27, 2026PoC AvailableRemote Exploitable
Overview
Mastodon versions < 4.5.8, < 4.4.15, and < 4.3.21 contain an Open Redirect vulnerability in the /web/* route due to improper handling of URL-encoded path segments, allowing unauthenticated attackers to redirect users.
Severity & Score
Severity: Medium
CVSS Score: 4.3
Impact
Redirect users to external domain.
Mitigation
Update Mastodon to versions 4.5.8, 4.4.15, 4.3.21.
References
Related Resources
Details
- CVE ID
- CVE-2026-33868
- Severity
- Medium
- CVSS Score
- 4.3
- Type
- open_redirect
- Status
- new
CWE
- CWE-601
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N