OAuth Scope Bypass Fix: Missing tokenCan('follow') check in accountRemoveFollowerId API
Security Advisory
High
Pixelfed
Affected:
- Pixelfed < v0.14.1
Fixed in:
- v0.14.1
Referenced CVEs:
CVE-2026-93960 · 4.3
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from github.com, cleaned by our LLM pipeline, and translated to English. View original.