ISAC Alert - -
Pixelfed versions 0.12.4 and earlier contain a critical privacy vulnerability that impacts any and all Fediverse service providers that support follower-only messaging from follower-approvals-required accounts.
Ref: https://fokus.cool/2025/03/25/pixelfed-vulnerability.html
A tracking spreadsheet of domains by version is available at https://docs.google.com/spreadsheets/d/1t9wlqXC89EJwccxFAT_VknRdVAw6K6h-dMqVtaRVB-I/
If you host accounts that expect their followers-only posts to be non-visible to unapproved followers on remote Pixelfed services, consider informing your members.