What is CVE-2026-54742?
CVE-2026-54742: A vulnerability in Lemmy allows a community moderator to feature or unfeature posts in other communities via federated `CollectionAdd` and `CollectionRemove` activities using `CollectionType::Featured`. This affects versions 0.19.18 through 0.19.19 and 1.0.0-alpha.20, where the action can occur after `verify_mod_action` checks. Immediate update to the latest patched version is required.
Azərbaycanca: CVE-2026-54742: Lemmy platformasında federasiya vasitəsilə bir icma moderatorunun `CollectionAdd`/`CollectionRemove` fəaliyyətlərindən istifadə edərək digər icmalarda postları önə çıxarmağa (feature) imkan verən zəiflikdir. 0.19.18-0.19.19 və 1.0.0-alpha.20 versiyaları təsirlənir, moderator `verify_mod_action` yoxlamasından sonra belə bu əməliyyatı edə bilir. Təsirlənən versiyalardan ən son təhlükəsizlik yamalarına təcili keçid etmək lazımdır.
FAQ2
Through which operations is CVE-2026-54742 exploited in the Lemmy platform?
The vulnerability is exploited via federated `CollectionAdd` and `CollectionRemove` activities using `CollectionType::Featured` to feature posts in other communities.
Which Lemmy versions are affected by CVE-2026-54742?
Versions 0.19.18 through 0.19.19 and 1.0.0-alpha.20 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.