PatchSiren

mastodon CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH mastodon CVE published 2026-06-15

CVE-2026-47777

CVE-2026-47777 is a HIGH severity vulnerability in Mastodon, a free, open-source social network server. An attacker could bypass the check for remote accounts' consent to be featured in a remote Collection, potentially allowing them to fake consent and manipulate Collection items. This vulnerability affects Mastodon servers running the main branch or nightly builds with the experimental 'Collections' feat [truncated]