Wow, this Pixelfed bug is *nasty*. Allowed users to access private posts of remote users they're not following so long as another user on the same Pixelfed server legitimately followed that account.

If you're running a Pixelfed server, definitely upgrade immediately now that the vulnerability is publicly known.

fokus.cool/2025/03/25/pixelfed

0

If you have a fediverse account, you can quote this note from your own instance. Search https://digipres.club/users/misty/statuses/114225132052734318 on your instance and quote it. (Note that quoting is not supported in Mastodon.)