LemmyNet lemmy是LemmyNet组织的一个去中心化的链接聚合与讨论社区平台。 LemmyNet lemmy 0.19.19之前版本和1.0.0-alpha.20之前版本存在授权问题漏洞,该漏洞源于未验证帖子所属社区,导致社区版主可通过联邦CollectionAdd和CollectionRemove活动将其他社区的帖子置顶或取消置顶,或撤销其他社区的策展决定。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54739 | 6.9 MEDIUM | Lemmy: Login Endpoint User Enumeration via HTTP Response Code Differential |
| CVE-2026-54740 | 6.5 MEDIUM | Lemmy: Lower-ranked federated moderator can remove higher-ranked moderators |
| CVE-2026-54738 | 6.5 MEDIUM | Lemmy: Rate limit bypass via X-Forwarded-For header spoofing in actix-web ConnectionInfo |
| CVE-2026-54743 | 6.4 MEDIUM | Lemmy: Stored XSS via markdown image alt-text in lemmy-ui html5-embed |
| CVE-2026-54741 | 5.3 MEDIUM | Lemmy: Blocked users can edit private messages sent before the block |
No comments yet