CVE-2023-29218: Twitter Recommendation Algorithm
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputation score) by arranging for multiple Twitter accounts to coordinate negative signals regarding a target account, such as unfollowing, muting, blocking, and reporting, as exploited in the wild in March and April 2023. NOTE: Vendor states that allowing users to unfollow, mute, block, and report tweets and accounts and the impact of these negative engagements on Twitter’s ranking algorithm is a conscious design decision, rather than a security vulnerability.
Affected products
- Twitter Recommendation Algorithm: up to and including 2023-03-31
Published 2023-04-03. Last modified 2026-06-17.