Mastodon version < 4.5.8, < 4.4.15, < 4.3.21 is vulnerable to unauthenticated Open Redirect vulnerability (CWE-601) exists in the /web/* route due to improper handling of URL-encoded path segments.
id: CVE-2026-33868
info:
name: Mastodon - Open Redirect
author: theamanrawat
severity: medium
...