CVE-2023-29218General(twitter / recommendation_algorithm)

LOWCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (4 mentions)

Immediate actions

  • Prioritize remediation for twitter recommendation_algorithm systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputation score) by arranging for multiple Twitter accounts to coordinate negative signals regarding a target account, such as unfollowing, muting, blocking, and reporting, as exploited in the wild in March and April 2023. NOTE: Vendor states that allowing users to unfollow, mute, block, and report tweets and accounts and the impact of these negative engagements on Twitter’s ranking algorithm is a conscious design decision, rather than a security vulnerability.

3.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • recommendation_algorithm

Threat summary

  • Active exploitation appears in 1 classified signals
  • 9 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • General: 8 classified signals
  • Peaked 1d ago at 4 mentions (2026-05-25); latest day: 4
  • 9 total mentions across 3 days

Affected systems

Vendors
Products
recommendation_algorithm

Deep dive

Activity timeline9 mentions / 3d
01234Mentions · 2026-02-26: 1Mentions · 2026-05-25: 4Mentions · 2026-05-26: 4Active Exploitation · 2026-02-26: 1Technical Details · 2026-05-26: 102-2605-2505-26
Signal classification2 categories
General
888.9%
Active Exploitation
111.1%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-261
Active Exploitation1
2026-05-254
General4
2026-05-264
General4
Full discourse9 posts
  • Takvim@takvim
    General

    Özel Haber | "Algı"ritmanın "X"-ray'i * Kod adı CVE-2023-29218: X, CIA ve FETÖ'nün Türkiye operasyonu * Sana Özel değil Pensilvanya'ya özel: Gölge ban ile hedefleri milli irade * Muhalif sesler yükseltildi: 4 aşamalı taktik https://www.takvim.com.tr/guncel/2026/05/25/sana-ozel-degil-pensilvanyaya-ozel-x-algoritmasina-feto-tuzagi-yerli-ve-milli-hesaplara-sansur https://t.co/D9lfRCQGK7

    Post summary

    A news headline references CVE-2023-29218 but provides no additional details, exploit information, or mitigation guidance.

    07007865.2K
    264.5K followersView on X
  • Emrah Atila@e_atila
    General

    Peki ne yapılmalı? CVE-2023-29218 derhal kapatılmalı. X, bu açığı "tasarım kararı" olarak savunuyor; ancak koordineli bot saldırılarına kapı açan bu tasarım hem bilgi ekosistemini hem demokratik süreçleri tehdit ediyor. Yani bu yalnızca teknik bir güvenlik açığı değil; Türkiye'nin bilgi egemenliğine yönelik sistematik bir saldırıdır. Türkiye, bu açığın kendi vatandaşlarına karşı kullanıldığını belgelerle ortaya koyarak uluslararası platformlarda hesap sorabilir. Bağımsız araştırmaların sürdürülmesi ve bu bulguların kamuoyuyla paylaşılması kritik önem taşıyor.   X'in öneri sistemi, kullanıcının bir gönderiye verdiği tepkinin olumlu mu olumsuz mu olduğunu anlayacak şekilde geliştirilmeli. Her etkileşimi körü körüne beğeni sinyali sayan mevcut yapı, FETÖ gibi organize aktörlerin eline güçlü bir silah veriyor. Kişiselleştirme tercihi kullanıcıya bırakılmalı; "Takip Ettiklerin" sekmesi varsayılan akış olarak sunulabilmeli.

    Post summary

    The post warns that CVE-2023-29218 poses a systemic threat capable of enabling coordinated bot attacks, yet it provides no concrete technical details, PoC, exploit code, or remediation guidance.

    31725621.6K
    4.7K followersView on X
  • Esra Aydın (Hamuşan)@Arnavut_Esra
    General

    CVE-2023-29218 derhal kapatılmalı. @elonmusk @X

    Post summary

    A brief call to action urging immediate closure of CVE‑2023‑29218, without detailed technical or exploit information.

    150252916
    20.9K followersView on X
  • ✧ VÎCTOR ✧@xuxi_main
    General

    @asliibaykal @GOCMEN66 CVE-2023-29218 Nedir X platformunun öneri algoritmasında belgelenmiş bir güvenlik açığıdır. Bu açık, organize çok sayıda hesabın toplu olarak “unfollow, mute, block, report” gibi negatif etkileşimler yapmasıyla hedef hesabın görünürlüğünü ve güven puanını düşürmesine imkân tanır. https://t.co/GQh8mqOIQ9

    Post summary

    The tweet describes CVE‑2023‑29218 as a flaw in X’s recommendation engine that lets attackers bulk‑unfollow, mute, block, or report accounts to degrade a target’s visibility and trust score.

    051171400
    34.9K followersView on X
  • Sesil@Detayy1453
    General

    @Arnavut_Esra @elonmusk @X CVE-2023-29218 derhal kapatılmalı. @elonmusk @X

    Post summary

    The tweet merely calls for action on CVE-2023-29218 without providing any technical detail, evidence of exploitation, or mitigation guidance.

    00030110
    22.1K followersView on X
  • I Can See You@Lookin_In91862
    Active Exploitation

    @GeneralPatton83 So They Got This Thing And Now They're Makin These Bots To Do The Thing And It's Fuckin Everyone Up https://www.cve.org/CVERecord?id=CVE-2023-29218 https://t.co/IpJ7w4bhTm

    Post summary

    The tweet indicates that CVE-2023-29218 is being actively exploited via bots, but offers no technical details, PoC, or patch information.

    1001186
    1.1K followersView on X
  • Fatih Öz@Fatih_Oz_Usa
    General

    8️⃣ Özetle. CVE-2023-29218 gerçektir, koordineli bot saldırısıyla hesap itibarı düşürülebilir, bu evrensel bir risktir — bunlar doğru. “40 bin bot ordusu,” “100 hesapla tam susturma,” belirli hesapların FETÖ tarafından özellikle desteklendiği, yeni hesaplarda %90 muhalif içerik yönlendirmesi — bunların hiçbirinin metodolojisi, bağımsız doğrulaması ve somut teknik kanıtı yok. Tek kaynak bağımsız değildir. Koordineli yayılım organik gazetecilik değildir. Gerçek riski görebilmek için onu siyasi araçsallaştırmadan ayırt etmek zorundayız. NOT: Bu konuyu bağımsız kaynaklardan takip etmek isteyenler için: 🔗 NVD — CVE-2023-29218 resmi kaydı 🔗 GitHub Advisory Database — GHSA-rfh2-62gc-x7hw 🔗 Freedom House — Freedom on the Net: Turkey 🔗 Citizen Lab — Turkey araştırmaları 🔗 Stanford Internet Observatory — Coordinated Inauthentic Behavior raporları. Hepsi açık erişimli. Hepsi bağımsız. Hepsi doğrulanabilir. Bir haberi değerlendirmenin en güvenilir yolu: kaynağa gitmektir. -SON- #DijitalGüvenlik #AlgoritmaManipülasyonu #MedyaAnalizi #FactCheck #CVE202329218 #X #DezenformasizasyonuDurdur #hizmethareketi

    Post summary

    The message confirms CVE‑2023‑29218’s authenticity but rejects unverified reports of coordinated bot attacks, offering no technical, exploit, or mitigation details.

    1000062
    461 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-5426 2 - CVE-2023-29218 3 - CVE-2026-2031 4 - CVE-2026-41096 5 - CVE-2024-53141 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists five trending CVEs without offering PoC, exploit, patch, or technical detail information.

    00010199
    1.7K followersView on X
  • Fatih Öz@Fatih_Oz_Usa
    General

    DİKKAT 3️⃣ Hesap engelleme ve algoritmik baskı gerçek bir sorun. Bize destek veren hesaplar da, karşıt görüşlü hesaplar da yasaklanıyor. İşte bu yüzden bu sorunu “FETÖ bunu yapıyor” çerçevesine sıkıştırmak yerine herkesin ortak sorunu olarak ele almak gerekiyor. CVE-2023-29218 açığı gerçektir ve bu açık koordinasyon kapasitesi olan her aktör tarafından kullanılabilir. devlet içi klikler dahil. Hatta herkesçe artık bilinen ve kabul edilen, iktidar adına maaşlı çalışan Trol merkezlerinde iktidar adına bunlar çok organize bunu kullanıyor. Hiçbir yerel organizasyon, devlet destekli bir troll organizasyonuyla yarışamaz. Yani ortaya atılan “Fetö yapıyor iddiaları” aslında iktidar medyasının itirafı. Dervişin fikri neyse zikri odur. Odaklanılması gereken nokta budur.

    Post summary

    The post confirms CVE-2023-29218 exists and could be abused by any actor, but offers no technical details, fixes, or proof of exploitation.

    0000082
    461 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptwitterrecommendation_algorithm---

Explore more