CVE-2026-93960

Source
https://cve.org/CVERecord?id=CVE-2026-93960
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93960.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93960
Published
2026-09-20T03:00:19Z
Modified
2026-09-24T03:30:47Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Pixelfed OAuth Scope ApiV1Controller.php instancePeers missing authentication
Details

A vulnerability was identified in Pixelfed up to 0.12.11. Impacted is the function instancePeers of the file app/Http/Controllers/Api/ApiV1Controller.php of the component OAuth Scope Handler. Such manipulation of the argument ID leads to missing authentication. The attack may be performed from remote. The exploit is publicly available and might be used. Upgrading to version 0.12.10 is recommended to address this issue. The name of the patch is 68dca5097305fa0065d029587b2233524636025a. Upgrading the affected component is advised.

Database specific
{
    "cna_assigner":  "VulDB",
    "cwe_ids":  [
        "CWE-287",
        "CWE-306"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93960.json"
}
References

Affected packages

Git / github.com/pixelfed/pixelfed

Affected ranges

Type
GIT
Repo
https://github.com/pixelfed/pixelfed
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0.12.0"
        },
        {
            "last_affected":  "0.12.0"
        },
        {
            "introduced":  "0.12.1"
        },
        {
            "last_affected":  "0.12.1"
        },
        {
            "introduced":  "0.12.2"
        },
        {
            "last_affected":  "0.12.2"
        },
        {
            "introduced":  "0.12.3"
        },
        {
            "last_affected":  "0.12.3"
        },
        {
            "introduced":  "0.12.4"
        },
        {
            "last_affected":  "0.12.4"
        },
        {
            "introduced":  "0.12.5"
        },
        {
            "last_affected":  "0.12.5"
        },
        {
            "introduced":  "0.12.6"
        },
        {
            "last_affected":  "0.12.6"
        },
        {
            "introduced":  "0.12.7"
        },
        {
            "last_affected":  "0.12.7"
        },
        {
            "introduced":  "0.12.8"
        },
        {
            "last_affected":  "0.12.8"
        },
        {
            "introduced":  "0.12.9"
        },
        {
            "last_affected":  "0.12.9"
        },
        {
            "introduced":  "0.12.10"
        },
        {
            "last_affected":  "0.12.10"
        },
        {
            "introduced":  "0.12.11"
        },
        {
            "last_affected":  "0.12.11"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.12.0
0.12.1
0.12.10
0.12.11
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
v0.*
v0.12.0
v0.12.1
v0.12.2
v0.12.3
v0.12.4
v0.12.5
v0.12.6
v0.12.7
v0.12.8
v0.12.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93960.json"