VYPR

Misskey

by Misskey Dev

Source repositories

CVEs (35)

  • CVE-2026-46712LowAug 3, 2026
    risk 0.08cvss epss 0.00

    Misskey is an open source, federated social media platform. Versions 2025.3.2 and later, but prior to 2026.5.4, contain a vulnerability where a lack of proper permission checks allows access to certain data points from the Direct Messages (formerly Chat) feature, regardless of…

  • CVE-2026-57575MedJul 10, 2026
    risk 0.00cvss epss 0.00

    Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a Server-Side Request Forgery (SSRF) vulnerability in URL preview functionality in UrlPreviewService. Due to missing network restrictions before establishing outbound connections, a…

  • CVE-2026-57574HigJul 10, 2026
    risk 0.00cvss epss 0.00

    Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a vulnerability in Time-based One-Time Password (TOTP) authentication in UserAuthService where insufficient validation of used tokens allows the reuse of a single-use code within its…

  • CVE-2025-46559MedMay 5, 2025
    risk 0.00cvss 5.4epss 0.00

    Misskey is an open source, federated social media platform. Starting in version 12.31.0 and prior to version 2025.4.1, missing validation in `Mk:api` allows malicious AiScript code to access additional endpoints that it isn't designed to have access to. The missing validation…

  • CVE-2025-46340HigMay 5, 2025
    risk 0.00cvss 7.2epss 0.00

    Misskey is an open source, federated social media platform. Starting in version 12.0.0 and prior to version 2025.4.1, due to an oversight in the validation performed in `UrlPreviewService` and `MkUrlPreview`, it is possible for an attacker to inject arbitrary CSS into the…

  • CVE-2025-24897HigFeb 11, 2025
    risk 0.00cvss 8.2epss 0.00

    Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, due to a lack of CSRF protection and the lack of proper security attributes in the authentication cookies of Bull's dashboard, some of the APIs of…

  • CVE-2025-24896HigFeb 11, 2025
    risk 0.00cvss 8.1epss 0.01

    Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, a login token named `token` is stored in a cookie for authentication purposes in Bull Dashboard, but this remains undeleted even after logout is…

  • CVE-2024-32983HigJun 3, 2024
    risk 0.00cvss 8.2epss 0.00

    Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSON structures of incoming signed ActivityPub activity objects before processing them, allowing threat actors to spoof the contents of signed activities and…

  • CVE-2024-25636HigFeb 19, 2024
    risk 0.00cvss 7.1epss 0.01

    Misskey is an open source, decentralized social media platform with ActivityPub support. Prior to version 2024.2.0, when fetching remote Activity Streams objects, Misskey doesn't check that the response from the remote server has a `Content-Type` header value of the Activity…

  • CVE-2023-52139CriDec 29, 2023
    risk 0.00cvss 9.0epss 0.01

    Misskey is an open source, decentralized social media platform. Third-party applications may be able to access some endpoints or Websocket APIs that are incorrectly specified as [kind](https://github.com/misskey-dev/misskey/blob/406b4bdbe79b5b0b68fcdcb3c4b6e419460a0258/packages/b…

  • CVE-2023-43793HigOct 4, 2023
    risk 0.00cvss 7.5epss 0.01

    Misskey is an open source, decentralized social media platform. Prior to version 2023.9.0, by editing the URL, a user can bypass the authentication of the Bull dashboard, which is the job queue management UI, and access it. Version 2023.9.0 contains a fix. There are no known…

  • CVE-2023-24812HigFeb 22, 2023
    risk 0.00cvss 8.8epss 0.01

    Misskey is an open source, decentralized social media platform. In versions prior to 13.3.3 SQL injection is possible due to insufficient parameter validation in the note search API by tag (notes/search-by-tag). This has been fixed in version 13.3.3. Users are advised to…

  • CVE-2023-24811HigFeb 22, 2023
    risk 0.00cvss 7.1epss 0.00

    Misskey is an open source, decentralized social media platform. In versions prior to 13.3.2 the URL preview function is subject to a cross site scripting vulnerability due to insufficient URL validation. Arbitrary JavaScript is executed when a malicious URL is loaded in the…

  • CVE-2021-39195HigSep 7, 2021
    risk 0.00cvss 7.7epss 0.01

    Misskey is an open source, decentralized microblogging platform. In affected versions a Server-Side Request Forgery vulnerability exists in "Upload from URL" and remote attachment handling. This could result in the disclosure of non-public information within the internal…

  • CVE-2021-39169HigAug 27, 2021
    risk 0.00cvss 8.0epss 0.01

    Misskey is a decentralized microblogging platform. In versions of Misskey prior to 12.51.0, malicious actors can use the web client built-in dialog to display a malicious string, leading to cross-site scripting (XSS). XSS could compromise the API request token. This issue has…

Page 2 of 2