CVE-2025-54888
Last modified
CVE-2025-54888 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Fedify is a TypeScript library for building federated server apps powered by ActivityPub. In versions below 1.3.20, 1.4.0-dev.585 through 1.4.12, 1.5.0-dev.636 through 1.5.4, 1.6.0-dev.754 through 1.6.7, 1.7.0-pr.251.885 through 1.7.8 and 1.8.0-dev.909 through 1.8.4, an authentication bypass vulnerability allows any unauthenticated attacker to impersonate any ActivityPub actor by sending forged activities signed with their own keys. EPSS estimates a 0.71% chance of exploitation in the next 30 days.
Description
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. In versions below 1.3.20, 1.4.0-dev.585 through 1.4.12, 1.5.0-dev.636 through 1.5.4, 1.6.0-dev.754 through 1.6.7, 1.7.0-pr.251.885 through 1.7.8 and 1.8.0-dev.909 through 1.8.4, an authentication bypass vulnerability allows any unauthenticated attacker to impersonate any ActivityPub actor by sending forged activities signed with their own keys. Activities are processed before verifying the signing key belongs to the claimed actor, enabling complete actor impersonation across all Fedify instances. This is fixed in versions 1.3.20, 1.4.13, 1.5.5, 1.6.8, 1.7.9 and 1.8.5.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-54888?
How severe is CVE-2025-54888?
How do I fix CVE-2025-54888?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-54882Himmelblau is an interoperability suite for Microsoft Azure …7.1
- CVE-2025-54883Vision UI is a collection of enterprise-grade, dependency-fr…9.3
- CVE-2025-54884Vision UI is a collection of enterprise-grade, dependency-fr…8.7
- CVE-2025-54885Thinbus Javascript Secure Remote Password is a browser SRP6a…6.9
- CVE-2025-54886skops is a Python library which helps users share and ship t…8.4
- CVE-2025-54887jwe is a Ruby implementation of the RFC 7516 JSON Web Encryp…9.1
- CVE-2025-54889Improper Neutralization of Input During Web Page Generation …4.8
- CVE-2025-5489Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-54890Improper Neutralization of Input During Web Page Generation …4.8
- CVE-2025-54891Improper Neutralization of Input During Web Page Generation …4.8
- CVE-2025-54892Improper Neutralization of Input During Web Page Generation …4.8
- CVE-2025-54893Improper Neutralization of Input During Web Page Generation …4.8
Are you affected by CVE-2025-54888?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
