CVE-2025-25194

CVSS 3.1 Score 4 of 10 (medium)

Details

Published Feb 10, 2025
CWE ID 918

Summary

CVE-2025-25194 is a server-side request forgery vulnerability affecting Lemmy, a link aggregator and forum for the fediverse. The issue stems from a dependency on activitypub_federation, a Rust-based framework for ActivityPub federation, which is present in Lemmy versions 0.19.8 and prior, as well as activitypub_federation versions 0.6.2 and prior. This flaw enables users to bypass any predefined URL path or security anti-Localhost mechanism and execute arbitrary GET requests to any Host, Port, and URL via a Webfinger Request. At the time of publication, no fix has been released to address this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share