MASTODON 4.7.1 UPDATE BRINGS SECURITY FIXES TO TOMB RAIDER SOCIAL
[ 1 September 2026 ]
Tomb Raider Social has been updated to Mastodon version 4.7.1. The release addresses three security issues, including a password authentication bypass affecting two-factor authentication for LDAP, PAM and SSO accounts. It also fixes a denial-of-service issue involving the processing of certain JSON-LD activities, and prevents disabled staff accounts from retaining access to the administration API.
The update also contains several general fixes. Users joining through invitations that do not require approval will now be asked to provide a written reason where required, while domain filters for blocked email addresses are retained when moving between pages. Other changes address Docker configuration, interrupted database migrations and an account creation error involving ActiveRecord encryption during the Mastodon setup process.
Tomb Raider Social is a decentralised, open-source social networking platform powered by Mastodon where Tomb Raider content creators, fans, and community members can connect, share content, and take part in discussions about the series. Users interact through chronological timelines without algorithmically curated feeds or advertising.

