📦 Misskey

by Misskey

🔍 What is Misskey?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-25306

CRITICAL CVSS 9.3 Mar 10, 2025

This vulnerability in Misskey allows attackers to forge ActivityPub objects by manipulating the relationship between 'id' and 'url' fields, bypassing authorization checks. It affects all Misskey insta...

CVE-2024-52591

CRITICAL CVSS 9.3 Dec 18, 2024

This vulnerability in Misskey allows attackers to create fake user profiles and forged notes that appear to originate from different instances or users. Attackers can fully control these spoofed objec...

CVE-2023-52139

CRITICAL CVSS 9.0 Dec 29, 2023

This vulnerability in Misskey allows third-party applications to access endpoints or Websocket APIs without proper user permission due to incorrect 'kind' or 'secure' specifications. It enables unauth...

CVE-2023-49079

CRITICAL CVSS 9.3 Nov 29, 2023

This vulnerability in Misskey allows arbitrary users to impersonate any remote user due to missing signature validation in the decentralized social media platform. All Misskey instances running vulner...

CVE-2025-46340

HIGH CVSS 7.2 May 5, 2025

This CVE describes a CSS injection vulnerability in Misskey's URL preview functionality. Attackers can inject arbitrary CSS to create fake error messages that could deceive users into revealing creden...

CVE-2025-24896

HIGH CVSS 8.1 Feb 11, 2025

Misskey versions 12.109.0 through 2025.2.0-alpha.0 fail to delete authentication tokens from cookies after logout, allowing session persistence. This primarily affects users who log in from shared or ...

CVE-2025-24897

HIGH CVSS 8.2 Feb 11, 2025

This CSRF vulnerability in Misskey's Bull dashboard allows attackers to perform unauthorized actions by tricking authenticated users into submitting malicious requests. It affects Misskey instances ru...

CVE-2024-32983

HIGH CVSS 8.2 Jun 3, 2024

This vulnerability in Misskey allows attackers to spoof signed ActivityPub activity objects by exploiting improper JSON normalization. Attackers can impersonate legitimate users and post content as th...

CVE-2024-25636

HIGH CVSS 7.1 Feb 19, 2024

CVE-2024-25636 is a content-type validation vulnerability in Misskey that allows account takeover through ActivityPub protocol exploitation. Attackers can impersonate legitimate users on remote server...

CVE-2023-43793

HIGH CVSS 7.5 Oct 4, 2023

This vulnerability allows unauthenticated users to bypass authentication for the Bull dashboard job queue management interface in Misskey by editing URLs. This affects all Misskey instances running ve...

CVE-2023-24811

HIGH CVSS 7.1 Feb 22, 2023

This CVE describes a cross-site scripting (XSS) vulnerability in Misskey's URL preview function. Attackers can execute arbitrary JavaScript when users load malicious URLs in the 'View in Player' or 'V...

CVE-2023-25154

HIGH CVSS 7.1 Feb 22, 2023

This vulnerability allows attackers to execute arbitrary JavaScript code in victims' browsers by exploiting improper URL validation in Misskey's ActivityPub implementation. It affects all Misskey inst...

CVE-2021-39195

HIGH CVSS 7.7 Sep 7, 2021

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Misskey's 'Upload from URL' and remote attachment features. Attackers can exploit this to make the server send requests to inte...

CVE-2025-66402

MEDIUM CVSS 6.5 Dec 16, 2025

This vulnerability in Misskey allows unauthorized users to export and view posts from favorites or clips they shouldn't have access to. It affects Misskey instances running versions from 13.0.0-beta.1...

CVE-2025-66482

MEDIUM CVSS 6.5 Dec 16, 2025

This vulnerability allows attackers to bypass IP-based rate limiting in Misskey by forging X-Forwarded-For headers. It affects Misskey instances running versions 2025.9.1 through 2025.11.1 with defaul...

CVE-2025-46559

MEDIUM CVSS 5.4 May 5, 2025

This vulnerability in Misskey allows malicious AiScript code to bypass API endpoint restrictions by using directory traversal sequences (../) to access unauthorized endpoints like /files, /url, and /p...

CVE-2024-52590

MEDIUM CVSS 6.5 Dec 18, 2024

This vulnerability in Misskey allows attackers to create fake user profiles that appear to belong to different federated instances, enabling impersonation of legitimate users. Attackers can fully cont...

CVE-2024-52593

MEDIUM CVSS 5.3 Dec 18, 2024

This vulnerability in Misskey allows attackers to manipulate 'origin' links in notes and user profiles to point to arbitrary HTTPS URLs, even on different domains. This enables phishing attacks where ...