CVE-2025-30741
Pixelfed may allow unauthorized actor to view private posts and private users
4.3
MEDIUM
CVSS 3.1
EPSS 0.29%
Description
Pixelfed before 0.12.5 allows anyone to follow private accounts and see private posts on other Fediverse servers. This affects users elsewhere in the Fediverse, if they otherwise have any followers from a Pixelfed instance.
How to fix CVE-2025-30741
To remediate CVE-2025-30741, upgrade the affected package to a fixed version below.
- —upgrade to 0.12.5 or later
Is CVE-2025-30741 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.12.5
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |