The new Masto exploit is pretty bad. Please be sure to get your admin to update ASAP. In a nutshell, it allows remote impersonation/account takeover of any user not on a patched system.
No reports of it that I've seen in the wild, but it won't likely be long.
https://github.com/mastodon/mastodon/security/advisories/GHSA-3fjr-858r-92rw