Impact
A community moderator is able to mark or unmark posts from other communities as featured without verifying ownership, effectively allowing a moderator to hide or showcase content from other communities. This flaw is an authorization bypass (CWE-863) that can distort community feeds, mislead users, and undermine community trust.
Affected Systems
Lemmy installations running version 0.19.18 through 0.19.19 and 1.0.0‑alpha.20 are vulnerable. The issue was fixed in the 0.19.19 release and the 1.0.0‑alpha.20 release; later versions are not affected.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog. An attacker must possess moderator privileges in at least one community and send a forged CollectionAdd or CollectionRemove activity over federation; no external exploit code is required. While the impact is limited to content placement, it can be abused repeatedly to manipulate feeds across communities.
OpenCVE Enrichment