VYPR

Vendor CVEs

Misskey Dev

All CVEs

36 total · sorted by risk
  • CVE-2025-25306CriMar 10, 2025
    risk 0.60cvss 9.3epss 0.00

    Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate the relation between the `id` and `url` fields of ActivityPub objects. An attacker can forge an object where they claim authority in the `url` field even if the…

  • CVE-2024-52591CriDec 18, 2024
    risk 0.60cvss 9.3epss 0.00

    Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService.signedGet` and `HttpRequestService.getActivityJson` allows an attacker to create fake user profiles and forged notes. The spoofed users will appear to be from…

  • CVE-2023-49079CriNov 29, 2023
    risk 0.60cvss 9.3epss 0.00

    Misskey is an open source, decentralized social media platform. Misskey's missing signature validation allows arbitrary users to impersonate any remote user. This issue has been patched in version 2023.11.1-beta.1.

  • CVE-2026-46713CriAug 3, 2026
    risk 0.53cvss epss 0.00

    Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD signature validation and compaction process that allows spoofed activities to be accepted as valid. This issue has been fixed in…

  • CVE-2026-47746HigAug 3, 2026
    risk 0.51cvss epss 0.00

    Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, are vulnerable to timing attacks during JSON-LD signature validation and the compaction process. Because the JSON-LD parsing context is not shared between signature…

  • CVE-2026-28432HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.00

    Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerability that allows bypassing HTTP signature verification. Although this is a vulnerability related to federation, it affects all servers regardless of whether…

  • CVE-2026-28431HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.00

    Misskey is an open source, federated social media platform. All Misskey servers running versions 8.45.0 and later, but prior to 2026.3.1, contain a vulnerability that allows bad actors access to data that they ordinarily wouldn't be able to access due to insufficient permission…

  • CVE-2024-49363HigDec 18, 2024
    risk 0.48cvss 7.4epss 0.00

    Misskey is an open source, federated social media platform. In affected versions FileServerService (media proxy) in github.com/misskey-dev/misskey 2024.10.1 or earlier did not detect proxy loops, which allows remote actors to execute a self-propagating reflected/amplified…

  • CVE-2023-24810HigFeb 22, 2023
    risk 0.46cvss 7.1epss 0.00

    Misskey is an open source, decentralized social media platform. Due to insufficient validation of the redirect URL during `miauth` authentication in Misskey, arbitrary JavaScript can be executed when a user allows the link. All versions below 13.3.1 (including 12.x) are…

  • CVE-2023-25154HigFeb 22, 2023
    risk 0.46cvss 7.1epss 0.00

    Misskey is an open source, decentralized social media platform. In versions prior to 13.5.0 the link to the instance to the sender that appears when viewing a user or note received through ActivityPub is not properly validated, so by inserting a URL with a javascript scheme an…

  • CVE-2024-52590MedDec 18, 2024
    risk 0.42cvss 6.5epss 0.00

    Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService.signedGet` allows an attacker to create fake user profiles that appear to be from a different instance than the one where they actually exist. These profiles…

  • CVE-2024-52579MedDec 18, 2024
    risk 0.42cvss 6.4epss 0.00

    Misskey is an open source, federated social media platform. Some APIs using `HttpRequestService` do not properly check the target host. This vulnerability allows an attacker to send POST or GET requests to the internal server, which may result in a SSRF attack.It allows an…

  • CVE-2019-1020010MedJul 29, 2019
    risk 0.40cvss 6.1epss 0.01

    Misskey before 10.102.4 allows hijacking a user's token.

  • CVE-2025-66482MedDec 16, 2025
    risk 0.35cvss 6.5epss 0.00

    Misskey is an open source, federated social media platform. Attackers who use an untrusted reverse proxy or not using a reverse proxy at all can bypass IP rate limiting by adding a forged X-Forwarded-For header. Starting with version 2025.9.1, an option (`trustProxy`) has been…

  • CVE-2025-66402MedDec 16, 2025
    risk 0.35cvss 6.5epss 0.00

    Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025.12.0, an actor who does not have permission to view favorites or clips can can export the posts and view the contents. Version 2025.12.0 fixes the issue.

  • CVE-2026-48115MedAug 3, 2026
    risk 0.34cvss epss 0.00

    Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a vulnerability in the Server Announcements API where insufficient permission checks allow attackers to access limited portions of…

  • CVE-2024-52593MedDec 18, 2024
    risk 0.34cvss 5.3epss 0.00

    Misskey is an open source, federated social media platform.In affected versions missing validation in `NoteCreateService.insertNote`, `ApPersonService.createPerson`, and `ApPersonService.updatePerson` allows an attacker to control the target of any "origin" links (such as the…

  • CVE-2024-52592MedDec 18, 2024
    risk 0.34cvss 5.3epss 0.00

    Misskey is an open source, federated social media platform. In affected versions missing validation in `ApInboxService.update` allows an attacker to modify the result of polls belonging to another user. No authentication is required, except for a valid signature from any actor…

  • CVE-2025-46553MedMay 5, 2025
    risk 0.33cvss 6.1epss 0.00

    @misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1, a logic error in the main `summaly` function causes the `allowRedirects` option to never be passed to any plugins, and as a result, isn't enforced. Misskey…

  • CVE-2026-28433MedMar 10, 2026
    risk 0.28cvss 4.3epss 0.00

    Misskey is an open source, federated social media platform. All Misskey servers running versions 10.93.0 and later, but prior to 2026.3.1, contain a vulnerability that allows importing other users' data due to lack of ownership validation. The impact of this vulnerability is…

  • CVE-2026-46714MedAug 3, 2026
    risk 0.26cvss epss 0.00

    Misskey is an open source, federated social media platform. IVersions 8.63.0 and later, but prior to 2026.5.4, contain a vulnerability that can cause the Misskey web client to slow down or crash when it applies a malformed theme. This issue has been fixed in version 2026.5.4.

  • CVE-2026-46712LowAug 3, 2026
    risk 0.08cvss epss 0.00

    Misskey is an open source, federated social media platform. Versions 2025.3.2 and later, but prior to 2026.5.4, contain a vulnerability where a lack of proper permission checks allows access to certain data points from the Direct Messages (formerly Chat) feature, regardless of…

  • CVE-2026-57575MedJul 10, 2026
    risk 0.00cvss epss 0.00

    Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a Server-Side Request Forgery (SSRF) vulnerability in URL preview functionality in UrlPreviewService. Due to missing network restrictions before establishing outbound connections, a…

  • CVE-2026-57574HigJul 10, 2026
    risk 0.00cvss epss 0.00

    Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a vulnerability in Time-based One-Time Password (TOTP) authentication in UserAuthService where insufficient validation of used tokens allows the reuse of a single-use code within its…

  • CVE-2025-46559MedMay 5, 2025
    risk 0.00cvss 5.4epss 0.00

    Misskey is an open source, federated social media platform. Starting in version 12.31.0 and prior to version 2025.4.1, missing validation in `Mk:api` allows malicious AiScript code to access additional endpoints that it isn't designed to have access to. The missing validation…

  • CVE-2025-46340HigMay 5, 2025
    risk 0.00cvss 7.2epss 0.00

    Misskey is an open source, federated social media platform. Starting in version 12.0.0 and prior to version 2025.4.1, due to an oversight in the validation performed in `UrlPreviewService` and `MkUrlPreview`, it is possible for an attacker to inject arbitrary CSS into the…

  • CVE-2025-24897HigFeb 11, 2025
    risk 0.00cvss 8.2epss 0.00

    Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, due to a lack of CSRF protection and the lack of proper security attributes in the authentication cookies of Bull's dashboard, some of the APIs of…

  • CVE-2025-24896HigFeb 11, 2025
    risk 0.00cvss 8.1epss 0.01

    Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, a login token named `token` is stored in a cookie for authentication purposes in Bull Dashboard, but this remains undeleted even after logout is…

  • CVE-2024-32983HigJun 3, 2024
    risk 0.00cvss 8.2epss 0.00

    Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSON structures of incoming signed ActivityPub activity objects before processing them, allowing threat actors to spoof the contents of signed activities and…

  • CVE-2024-25636HigFeb 19, 2024
    risk 0.00cvss 7.1epss 0.01

    Misskey is an open source, decentralized social media platform with ActivityPub support. Prior to version 2024.2.0, when fetching remote Activity Streams objects, Misskey doesn't check that the response from the remote server has a `Content-Type` header value of the Activity…

  • CVE-2023-52139CriDec 29, 2023
    risk 0.00cvss 9.0epss 0.01

    Misskey is an open source, decentralized social media platform. Third-party applications may be able to access some endpoints or Websocket APIs that are incorrectly specified as [kind](https://github.com/misskey-dev/misskey/blob/406b4bdbe79b5b0b68fcdcb3c4b6e419460a0258/packages/b…

  • CVE-2023-43793HigOct 4, 2023
    risk 0.00cvss 7.5epss 0.01

    Misskey is an open source, decentralized social media platform. Prior to version 2023.9.0, by editing the URL, a user can bypass the authentication of the Bull dashboard, which is the job queue management UI, and access it. Version 2023.9.0 contains a fix. There are no known…

  • CVE-2023-24812HigFeb 22, 2023
    risk 0.00cvss 8.8epss 0.01

    Misskey is an open source, decentralized social media platform. In versions prior to 13.3.3 SQL injection is possible due to insufficient parameter validation in the note search API by tag (notes/search-by-tag). This has been fixed in version 13.3.3. Users are advised to…

  • CVE-2023-24811HigFeb 22, 2023
    risk 0.00cvss 7.1epss 0.00

    Misskey is an open source, decentralized social media platform. In versions prior to 13.3.2 the URL preview function is subject to a cross site scripting vulnerability due to insufficient URL validation. Arbitrary JavaScript is executed when a malicious URL is loaded in the…

  • CVE-2021-39195HigSep 7, 2021
    risk 0.00cvss 7.7epss 0.01

    Misskey is an open source, decentralized microblogging platform. In affected versions a Server-Side Request Forgery vulnerability exists in "Upload from URL" and remote attachment handling. This could result in the disclosure of non-public information within the internal…

  • CVE-2021-39169HigAug 27, 2021
    risk 0.00cvss 8.0epss 0.01

    Misskey is a decentralized microblogging platform. In versions of Misskey prior to 12.51.0, malicious actors can use the web client built-in dialog to display a malicious string, leading to cross-site scripting (XSS). XSS could compromise the API request token. This issue has…