The vulnerability reported in this post has already been patched, but I think the post is still valuable for its post mortem on how the fix was handled. https://fokus.cool/2025/03/25/pixelfed-vulnerability.html
Pixelfed was not the only weak link in that scenario. @laurenshof has a pretty good breakdown of the three major issues exposed by the leak: https://fediversereport.com/fediverse-report-110/
If you have a fediverse account, you can quote this note from your own instance. Search https://merveilles.town/users/lrhodes/statuses/114265316056879823 on your instance and quote it. (Note that quoting is not supported in Mastodon.)