GHSL-2025-127: GHSL-2025-126_GHSL-2025-127: Unauthorized Mastodon account linking and domain creation in Lobsters
Published Sep 21, 2026
·Updated
Lobsters allowed attackers to link attacker-controlled Mastodon accounts to victims' accounts and let unauthenticated users create domain entries.
Affected Software
1 affected component
Lobsters Lobsters
Event History
Sep 21, 2026
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
Is authentication required to create domain entries?
No. The issue allows unauthenticated users to create domain entries.
2
What does an attacker need to carry out the account-linking attack?
The attacker needs control of a Mastodon account and targets a victim's Lobsters account for unauthorized linking.