For those using Private message on Lemmy, there is a major vulnerability. It seems that this instance still runs 18.5
I know that our beloved admins are volunteers and busy, so I don’t blame them for not updating, but while waiting for the update be aware that your PM are as public as your comments
On the matrix chat TheDude mentioned he was made aware of the vulnerability a while ago and has already patched it.
And in case you’re not aware, the direct messages here were never that private to begin with. Any admin of a federated instance has access so a bad actor could accomplish this with some dedication anyway.
Good to know thas it was patched. Indeed, an issue with federated app is that, instance admin could be dishonest and spy us (while proprietary app will do it). But to my understanding the bug was fully public so a message like call me , on 0123 456 789 could reveal your phone number
Even with this patched I would not advise stating your phone number ending redirecting full security.