id: CVE-2026-33868 info: name: Mastodon - Open Redirect author: theamanrawat severity: medium description: | Mastodon version < 4.5.8, < 4.4.15, < 4.3.21 is vulnerable to unauthenticated Open Redirect vulnerability (CWE-601) exists in the /web/* route due to improper handling of URL-encoded path segments. impact: | Redirect users to external domain. remediation: | Update Mastodon to versions 4.5.8, 4.4.15, 4.3.21. reference: - https://github.com/mastodon/mastodon/security/advisories/GHSA-xqw8-4j56-5hj6 - https://nvd.nist.gov/vuln/detail/CVE-2026-33868 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N cvss-score: 4.3 cve-id: CVE-2026-33868 epss-score: 0.00515 epss-percentile: 0.40765 cwe-id: CWE-601 metadata: verified: true vendor: mastodon product: mastodon shodan-query: html:"mastodon-" tags: cve,cve2026,mastodon,open-redirect,vuln,unauth http: - method: GET path: - "{{BaseURL}}/web/%2Finteract.sh:443" matchers-condition: and matchers: - type: regex regex: - '(?m)^(?:Location\s*?:\s*?)(?:https?:\/\/|\/\/)?(?:[a-zA-Z0-9\-_\.@]*)interact\.sh.*$' part: header - type: status condition: or status: - 302 - 301 # digest: 4a0a00473045022100cb05368fed45bc3cd50d59aa8152f9f7d7275c5e2039c1748d8fdc07ee9cb53b02201fadc6fec6e0c24253a2c002212b391dac7ae22eac549f1371fbc30b764c5306:922c64590222798bb761d5b6d8e72950