### Summary
Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account.
Every Mastodon version prior to 3.5.17 is vulnerable, as well as...
If your instance is not up to date (see footer), you can pass this along to your admins to check
Has it been confirmed this is a federation bug?
Based on this commit, which fixes the vulnerability, the bug seems to lie within the ActivityPub receive logic, specifically validation of remote resources.
Oh great, thanks.