Pixelfed before v0.12.5 has a vulnerability where it could leak your private posts, regardless of whether you are a Pixelfed user or not.
Admins should update ASAP.
When following someone from a different server on the Fediverse, the remote server decides whether you are allowed to do that. This enables features like locked accounts. Due to an implementation mistake, Pixelfed ignores this and allows anyone to follow even private accounts on other servers. If a legitimate user from a Pixelfed instance follows you on your locked account, anyone on that Pixelfed instance can read your private posts.
I wrote a blog post about how I found the vulnerability, how disclosure coordination went and general ramblings about Fediverse safety:
https://fokus.cool/2025/03/25/pixelfed-vulnerability.html
@fionafokus@mystical.garden Hey Fiona, quick update here.
Dansup did in fact change the ToS for Loops.video after I published my blog post. However, I have seen nothing to indicate that he did release the copyrights and licenses he claimed from his users, nor that he notified anyone of the issue.
I'm not sure what happened with that, if users got notifications and and explanation or not.
Perhaps someone who used Loops.video in that time period can check their email/ inboxes and confirm that Dan isn't holding on to everyone's personal data/ image/ content any more?
@fionafokus@mystical.garden Hey Fiona, quick update here.
Dansup did in fact change the ToS for Loops.video after I published my blog post. However, I have seen nothing to indicate that he did release the copyrights and licenses he claimed from his users, nor that he notified anyone of the issue.
I'm...