CVE-2025-62175 Details
Description
Mastodon is a free, open-source social network server based on ActivityPub. In versions before 4.4.6, 4.3.14, and 4.2.27, disabling or suspending a user account does not disconnect the account from the streaming API. This allows disabled or suspended accounts to continue receiving real-time updates through existing streaming connections and to establish new streaming connections, even though they cannot interact with other API endpoints. This undermines moderation actions, as administrators expect disabled or suspended accounts to be fully disconnected from the service. This issue has been patched in versions 4.4.6, 4.3.14, and 4.2.27. No known workarounds exist.
A vulnerability exists in Mastodon versions prior to 4.4.6, 4.3.14, and 4.2.27, where disabling or suspending a user account does not terminate the account's connection to the streaming API. As a result, these accounts can continue to receive real-time updates through existing streaming connections and establish new ones, despite being unable to interact with other API endpoints. This issue undermines moderation efforts, as administrators expect fully disabled or suspended accounts to be disconnected from the service.
Users can update to Mastodon versions 4.4.6, 4.3.14, or 4.2.27 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-273 | Improper Check for Dropped Privileges | [email protected] |
| CWE-274 | Improper Handling of Insufficient Privileges | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| joinmastodon mastodon | < 4.2.27 >= 4.3.0, < 4.3.14 >= 4.4.0, < 4.4.6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 20, 2025 | Initial Analysis | [email protected] |
| Oct 13, 2025 | New CVE Received | [email protected] |