this post was submitted on 15 May 2026
105 points (100.0% liked)

Announcements

711 readers
131 users here now

lemmy.zip annoucements

The same rules as the main instance apply here.

founded 2 years ago
MODERATORS
 

Hello All,

Due to the incredibly irresponsible disclosure of a security vulnerability for Piefed, we've had to take Piefed.zip offline until a fix can be put in place.

I'll update more once I have more information.

Many thanks

Demigodrick

top 22 comments
sorted by: hot top controversial new old
[–] Demigodrick@lemmy.zip 12 points 10 hours ago (1 children)

Update: there are additional reported vulnerabilities that I have been made aware of.

These have been shared with the Piefed Dev but no fixes yet in place.

Given this knowledge and the fact these exploits could be used to target vulnerable users and potentially access account data, I feel it is sensible to keep the instance offline until further fixes are in place.

[–] Blaze@lemmy.zip 7 points 10 hours ago

Makes sense, thank you!

[–] U7826391786239@lemmy.zip 1 points 49 minutes ago (1 children)

honestly i started using piefed because A) there's a .zip instance; and B) it's easier to follow people

given these security problems on top of the main dev's drama, i'll probably just delete my piefed and move back to lemmy

[–] frongt@lemmy.zip 1 points 43 minutes ago (1 children)

I'm on my phone so I can't review the issues, but I'm guessing they're mostly about the web interface. I would just not expose that to the world, only expose the necessary federation API endpoints.

[–] U7826391786239@lemmy.zip 1 points 39 minutes ago (1 children)

it's not even that, but the dev rimu banning people and people getting mad about it.. i'll stick with demigodrick, lemmy, and .zip. don't need any of that extra crap

[–] Kierunkowy74@lemmy.zip 1 points 5 minutes ago

Rimu has banned then from the flagship .social instance.

Do anyone care, that the Lemmy flagship is technically .ml?

[–] fiat_lux@lemmy.zip 25 points 19 hours ago (2 children)

A few months ago I mentioned in a thread about Piefed there were questionable system design choices that indicated that other parts of the system should be carefully examined for how they’re handling and sanitizing input. I'm assuming someone discovered one of the places that this was actively exploitable.

From what I've seen of the code, although Python is not my specialty, it might be worth delaying reactivation until it can demonstrate that it is at least somewhat resistant to the OWASP Top 10, especially Injection.

Irresponsible disclosure is annoying, but vastly better than discovery and exploitation by those who aren't going to disclose at all.

[–] Blaze@lemmy.zip 4 points 11 hours ago

You can look at https://codeberg.org/rimu/pyfedi/releases/tag/v1.6.25 to see the changes.

Basically, the 0-day was mostly someone running an LLM and trying to discover vulnerabilities without double checking them. Most of the things reported were not applicable (mentioning functions that don’t even exist), others were not applicable but led to some tangent hardening.

Lemmy also had a SSRF vulnerability a month ago: https://github.com/LemmyNet/lemmy/security/advisories/GHSA-q537-8fr5-cw35

[–] Blaze@piefed.social -1 points 12 hours ago

You can look at https://codeberg.org/rimu/pyfedi/releases/tag/v1.6.25 to see the changes.

Basically, the 0-day was mostly someone running an LLM and trying to discover vulnerabilities without double checking them. Most of the things reported were not applicable (mentioning functions that don't even exist), others were not applicable but led to some tangent hardening.

Lemmy also had a SSRF vulnerability a month ago: https://github.com/LemmyNet/lemmy/security/advisories/GHSA-q537-8fr5-cw35

[–] YoiksAndAway@lemmy.zip 17 points 23 hours ago

Thanks, as always, Demigodrick. I'll use my lemmy.zip alt until things are sorted.

[–] Schwim@lemmy.zip 12 points 23 hours ago* (last edited 22 hours ago)

EDIT: This has been resolved thanks to the helpful people on the matrix channel. For anyone else having problems, I just exported my lemmy profile, prettified both json files and manually moved over my blocks and subs then re-imported the modified lemmy file.

Hi there @Demigodrick@lemmy.zip , is there any way to use the piefed.zip export to import to lemmy.zip? I tried since it was mentioned in the email but it just states that the import failed when I try.

Just wondering if I can modify or remove some elements of the file so I can use it to get the blocks and subs imported from my piefed account.

Thanks!

[–] rumba@lemmy.zip 9 points 22 hours ago

GOAT

Most admins would stick their head in the sand. Thank you!

[–] FrederikNJS@lemmy.zip 7 points 20 hours ago* (last edited 20 hours ago) (1 children)

Thank you for taking proactive measures. I hope it gets resolved soon.

Are there any information around the nature of the vulnerability or the status of a fix?

[–] huppakee@lemmy.world 4 points 20 hours ago (1 children)

According to this comment https://piefed.social/comment/11352527 fix is expected to take a day.

[–] TachyonTele@piefed.social 6 points 19 hours ago

It was like 40 minutes in the end.

[–] Blaze@lemmy.zip 8 points 23 hours ago
[–] 1Fuji2Taka3Nasubi@lemmy.zip 1 points 15 hours ago

Thanks for the heads up.

[–] sirxdaemon@lemmy.ca 2 points 18 hours ago

Appreciate the email on this. I don't think I got an email from Piefed.social either. Heck I don't remember getting any from Lemmy.ca for Lemmy downtime. But perhaps they haven't ran into a similar situation.

[–] Az_1@piefed.social -1 points 15 hours ago (1 children)

Is there a timeline on when piefed.zip will come back online, a fix has now been released and piefed.social and piefed.blahaj.zone seem to have come back online

[–] Blaze@piefed.social 6 points 12 hours ago (1 children)

It's Saturday, I would give the .zip team some time

[–] Az_1@piefed.social 1 points 11 hours ago

I understand, apologies if I was being rude

[–] RickyRigatoni@retrolemmy.com 1 points 21 hours ago