Description
Mastodon version < 4.5.8, < 4.4.15, < 4.3.21 is vulnerable to unauthenticated Open Redirect vulnerability (CWE-601) exists in the /web/* route due to improper handling of URL-encoded path segments.
Mastodon version < 4.5.8, < 4.4.15, < 4.3.21 is vulnerable to unauthenticated Open Redirect vulnerability (CWE-601) exists in the /web/* route due to improper handling of URL-encoded path segments.
id: CVE-2026-33868
info:
name: Mastodon - Open Redirect
author: theamanrawat
severity: medium
description: |
Mastodon version < 4.5.8, < 4.4.15, < 4.3.21 is vulnerable to unauthenticated Open Redirect vulnerability (CWE-601) exists in the /web/* route due to improper handling of URL-encoded path segments.
impact: |
Redirect users to external domain.
remediation: |
Update Mastodon to versions 4.5.8, 4.4.15, 4.3.21.
reference:
- https://github.com/mastodon/mastodon/security/advisories/GHSA-xqw8-4j56-5hj6
- https://nvd.nist.gov/vuln/detail/CVE-2026-33868
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
cvss-score: 4.3
cve-id: CVE-2026-33868
epss-score: 0.00552
epss-percentile: 0.44339
cwe-id: CWE-601
metadata:
verified: true
vendor: mastodon
product: mastodon
shodan-query: html:"mastodon-"
tags: cve,cve2026,mastodon,open-redirect,vuln,unauth
http:
- method: GET
path:
- "{{BaseURL}}/web/%2Finteract.sh:443"
matchers-condition: and
matchers:
- type: regex
regex:
- '(?m)^(?:Location\s*?:\s*?)(?:https?:\/\/|\/\/)?(?:[a-zA-Z0-9\-_\.@]*)interact\.sh.*$'
part: header
- type: status
condition: or
status:
- 302
- 301
# digest: 4a0a0047304502210099838b5cd9813330e4842bb49207984d4d628b507a768930189a4b51b01e544702206c4cb404baa92c6f8e2d0d5fa2821992fac92edc684a1965f19a462f9a31cc58:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.