← Feed
@macfranc@poliversity.it
Post #3881965
2026-07-17 08:45 UTC
The spam campaign attacking Writefreely instances is out of control. Can you contact the admins you know?
@fediverse
Yesterday I received this message from my friend @elettrona@poliversity.it:
Are you the one running the "writefreely blogs" bot, aka writefreely@poliverso.org? Because there are tons of English accounts full of links that post nonstop.
And indeed, that account republishing posts from some Italian instances had a staggering amount of spam.
This is due to a very serious vulnerability that hasn't yet been patched by the developers, but which has (obviously) started to be exploited on a large scale.
I've notified all the Italian administrators of @writefreely@writing.exchange instances, but I'm having some difficulty contacting the foreign ones.
These are the ones with the most users:
https://write.otter.homes/read
https://infosec.press/read
https://blog.liberta.vip/read
https://write.tedomum.net/read
https://val-vgms.gay/read
https://bolha.blog/read
But there are many others.
Is there anyone among you who can try this or at least spread the word?Note: As I mentioned, the vulnerability has been known for a long time and is currently being exploited on a large scale.
https://github.com/writefreely/writefreely/issues/1649
Replies (1)
-
@macfranc@poliversity.it @elettrona@poliversity.it @writefreely@writing.exchange the issue has been addressed here: https://github.com/writefreely/writefreely/pull/1686
Still, the behaviour from the WriteFreely development team has been quite appalling - issue reported in May, addressed by a maintainer just 2 weeks ago, and going through a standard release process (which may take a couple of months) instead of being pushed as an urgent hotfix.
For now:
Workaround: pull the latest version of WriteFreely (git clone https://github.com/writefreely/writefreely) and build it (via make), then replace your WF executable with the newly built one.
Long-run (+ self-promotion): migrate to Madblog, but that’s not always a 1-1 option at the curent state because it still lack multiuser support.
Open ##3881964