7.1

CVE-2025-66402

Exploit
Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025.12.0, an actor who does not have permission to view favorites or clips can can export the posts and view the contents. Version 2025.12.0 fixes the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MisskeyMisskey Version >= 13.1.0 < 2025.12.0
MisskeyMisskey Version13.0.0 Update-
MisskeyMisskey Version13.0.0 Updatebeta16
MisskeyMisskey Version13.0.0 Updatebeta21
MisskeyMisskey Version13.0.0 Updatebeta22
MisskeyMisskey Version13.0.0 Updatebeta23
MisskeyMisskey Version13.0.0 Updatebeta24
MisskeyMisskey Version13.0.0 Updatebeta25
MisskeyMisskey Version13.0.0 Updatebeta26
MisskeyMisskey Version13.0.0 Updatebeta27
MisskeyMisskey Version13.0.0 Updatebeta28
MisskeyMisskey Version13.0.0 Updatebeta29
MisskeyMisskey Version13.0.0 Updatebeta30
MisskeyMisskey Version13.0.0 Updatebeta31
MisskeyMisskey Version13.0.0 Updatebeta32
MisskeyMisskey Version13.0.0 Updatebeta33
MisskeyMisskey Version13.0.0 Updatebeta34
MisskeyMisskey Version13.0.0 Updatebeta35
MisskeyMisskey Version13.0.0 Updatebeta36
MisskeyMisskey Version13.0.0 Updatebeta37
MisskeyMisskey Version13.0.0 Updatebeta38
MisskeyMisskey Version13.0.0 Updatebeta39
MisskeyMisskey Version13.0.0 Updatebeta40
MisskeyMisskey Version13.0.0 Updatebeta41
MisskeyMisskey Version13.0.0 Updatebeta42
MisskeyMisskey Version13.0.0 Updatebeta43
MisskeyMisskey Version13.0.0 Updaterc1
MisskeyMisskey Version13.0.0 Updaterc10
MisskeyMisskey Version13.0.0 Updaterc11
MisskeyMisskey Version13.0.0 Updaterc2
MisskeyMisskey Version13.0.0 Updaterc3
MisskeyMisskey Version13.0.0 Updaterc4
MisskeyMisskey Version13.0.0 Updaterc5
MisskeyMisskey Version13.0.0 Updaterc6
MisskeyMisskey Version13.0.0 Updaterc7
MisskeyMisskey Version13.0.0 Updaterc8
MisskeyMisskey Version13.0.0 Updaterc9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.137
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
security-advisories@github.com 7.1 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.