MASTODON 4.7.1 AND 4.7.2 UPDATES DEPLOYED ON TOMB RAIDER SOCIAL
[ 22 September 2026 ]
Tomb Raider Social has received two Mastodon updates, moving from version 4.7.0 to 4.7.1 and subsequently to 4.7.2. The releases include security updates and fixes affecting authentication, account management, email handling, data imports and other platform functions.
Mastodon 4.7.1 addresses three security issues. These include a password authentication bypass involving two-factor authentication for LDAP, PAM and single sign-on accounts, a denial-of-service issue when processing certain JSON-LD activities, and an issue that allowed disabled staff accounts to retain access to the administration API.
The 4.7.1 release also includes fixes covering account invitations, email domain filtering, Docker configuration, interrupted database migrations and account creation during Mastodon setup. One change ensures that users invited without requiring approval are still asked to provide a textual reason where required.
Mastodon 4.7.2 temporarily disables HEIF support and introduces further fixes. These address relative privacy policy links in subscription emails, email blocks interfering with account freezing or approval, server errors involving non-custom-filter JSON imports and duplicate status submissions, and account reattachment through Mastodon's command-line administration tools. The update also ensures that generated annual reports are deleted when an account is removed and that notifications are cleaned up when notification requests are deleted in bulk.
Tomb Raider Social is a decentralised, open-source social networking platform powered by Mastodon. It provides a space for Tomb Raider content creators, fans and community members to connect, share content and discuss the series. Posts are presented through chronological timelines rather than algorithmically curated feeds, and the platform does not display advertising.

