GHSL-2025-126: _GHSL-2025-127: Unauthorized Mastodon account linking and domain creation in Lobsters
Published Sep 21, 2026
·Updated
Lobsters allowed attackers to link attacker-controlled Mastodon accounts to victims' accounts and let unauthenticated users create domain entries.
Affected Software
1 affected component
Lobsters Lobsters
Event History
Sep 21, 2026
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
What capabilities could an unauthenticated attacker obtain?
An unauthenticated user could create domain entries. The issue also allowed an attacker to link an attacker-controlled Mastodon account to a victim's Lobsters account.
2
Does exploiting the account-linking issue require control of a Mastodon account?
Yes. The described attack involves linking an attacker-controlled Mastodon account to a victim's account.