I don't know who needs to hear this but #TruthSocial, which is running a forked version of Mastodon, does not from the source code appear to have appropriate mitigations in place for CVE-2023-36460, which theoretically allows attackers to create and overwrite any file Mastodon has access to, allowing Denial of Service and arbitrary Remote Code Execution https://nvd.nist.gov/vuln/detail/CVE-2023-36460 (probably other CVE's as well, but some rely on federation which Truth Social doesn't use?) #infosec
NVD - CVE-2023-36460

@ryanfb Don't tell anyone 🤐
@ubik @ryanfb
Why, it would be irresponsible not to make sure as many people as possible knew about this to make sure that the Truth Social team, who I am completely sure is competent and well-paid, is fully aware of the situation and will rectify the situation post-haste.