Critical severity9.3NVD Advisory· Published Mar 10, 2025· Updated Jun 17, 2026
CVE-2025-25306
CVE-2025-25306
Description
Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate the relation between the id and url fields of ActivityPub objects. An attacker can forge an object where they claim authority in the url field even if the specific ActivityPub object type require authority in the id field. Version 2025.2.1 addresses the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:misskey:misskey:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:misskey:misskey:*:*:*:*:*:*:*:*range: <2025.2.1
- (no CPE)range: =2025.2.1
- (no CPE)range: < 2025.2.1
Patches
Vulnerability mechanics
References
2- github.com/misskey-dev/misskey/releases/tag/2025.2.1nvdPatch
- github.com/misskey-dev/misskey/security/advisories/GHSA-6w2c-vf6f-xf26nvdThird Party Advisory
News mentions
0No linked articles in our index yet.