CVE-2026-93960 | Pixelfed up to 0.12.11 OAuth Scope ApiV1Controller.php instancePeers ID missing authentication (Issue 6643)
A vulnerability classified as problematic was found in Pixelfed up to 0.12.11. Impacted is the function instancePeers of the file app/Http/Controllers/Api/ApiV1Controller.php of the component OAuth Scope Handler. Such manipulation of the argument ID leads to missing authentication.
This vulnerability is listed as CVE-2026-93960. The attack may be performed from remote. In addition, an exploit is available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More