Skip to content

Proof of Concept for the type confusion vulnerability of ActivityPub implementations

License

Notifications You must be signed in to change notification settings

tesaguri/activitypub-type-confusion-poc

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

7 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

PoC for the type confusion vulnerability of ActivityPub

This repository contains PoCs for Mastodon's CVE-2024-25623 and Misskey's CVE-2024-25636, a then-common vulnerability among ActivityPub implementations (which is now tracked by the ActivityPub specification at w3c/activitypub#432).

The PoCs' instructions assume that you know the outline of the vulnerability. See the linked reports of the vulnerabilities for the outline. Mastodon's vulnerability is somewhat limited in its exploitability, so I recommend reading Misskey's one.

The PoCs

About

Proof of Concept for the type confusion vulnerability of ActivityPub implementations

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published