CVE-2023-29218
Twitter Recommendation Algorithm Manipulation Vulnerability
Record summary
CVE-2023-29218 has a selected CVSS score of 7.5 (high).
Description
The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputation score) by arranging for multiple Twitter accounts to coordinate negative signals regarding a target account, such as unfollowing, muting, blocking, and reporting, as exploited in the wild in March and April 2023. NOTE: Vendor states that allowing users to unfollow, mute, block, and report tweets and accounts and the impact of these negative engagements on Twitter’s ranking algorithm is a conscious design decision, rather than a security vulnerability.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 3, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 18, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
recommendation_algorithmBrowse twitter / recommendation_algorithm | VulnCheck | Version data not supplied | |