Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. @fedify/fedify
  4. ›
  5. CVE-2025-54888

CVE-2025-54888: @fedify/fedify has Improper Authentication and Incorrect Authorization

August 8, 2025 (updated August 11, 2025)

An authentication bypass vulnerability allows any unauthenticated attacker to impersonate any ActivityPub actor by sending forged activities signed with their own keys. Activities are processed before verifying the signing key belongs to the claimed actor, enabling complete actor impersonation across all Fedify instances

References

  • github.com/advisories/GHSA-6jcc-xgcr-q3h4
  • github.com/fedify-dev/fedify
  • github.com/fedify-dev/fedify/commit/226d9b84dbec52172a70138bba8861454afde42b
  • github.com/fedify-dev/fedify/security/advisories/GHSA-6jcc-xgcr-q3h4
  • nvd.nist.gov/vuln/detail/CVE-2025-54888

Code Behaviors & Features

Detect and mitigate CVE-2025-54888 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.3.20, all versions starting from 1.4.0-dev.585 before 1.4.13, all versions starting from 1.5.0-dev.636 before 1.5.5, all versions starting from 1.6.0-dev.754 before 1.6.8, all versions starting from 1.7.0-pr.251.885 before 1.7.9, all versions starting from 1.8.0-dev.909 before 1.8.5

Fixed versions

  • 1.3.20
  • 1.4.13
  • 1.5.5
  • 1.6.8
  • 1.7.9
  • 1.8.5

Solution

Upgrade to versions 1.3.20, 1.4.13, 1.5.5, 1.6.8, 1.7.9, 1.8.5 or above.

Weakness

  • CWE-287: Improper Authentication
  • CWE-863: Incorrect Authorization

Source file

npm/@fedify/fedify/CVE-2025-54888.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 19 Aug 2025 12:19:28 +0000.