Misskey

Misskey

27 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 09.03.2026 21:21:06
  • Zuletzt bearbeitet 13.03.2026 17:17:07

Misskey is an open source, federated social media platform. All Misskey servers running versions 10.93.0 and later, but prior to 2026.3.1, contain a vulnerability that allows importing other users' data due to lack of ownership validation. The impact...

  • EPSS 0.02%
  • Veröffentlicht 09.03.2026 21:19:43
  • Zuletzt bearbeitet 13.03.2026 17:18:06

Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerability that allows bypassing HTTP signature verification. Although this is a vulnerability related to federation, it affects all server...

  • EPSS 0.05%
  • Veröffentlicht 09.03.2026 21:17:32
  • Zuletzt bearbeitet 13.03.2026 17:18:44

Misskey is an open source, federated social media platform. All Misskey servers running versions 8.45.0 and later, but prior to 2026.3.1, contain a vulnerability that allows bad actors access to data that they ordinarily wouldn't be able to access du...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 15.12.2025 23:18:37
  • Zuletzt bearbeitet 06.01.2026 19:41:47

Misskey is an open source, federated social media platform. Attackers who use an untrusted reverse proxy or not using a reverse proxy at all can bypass IP rate limiting by adding a forged X-Forwarded-For header. Starting with version 2025.9.1, an opt...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 15.12.2025 23:09:57
  • Zuletzt bearbeitet 06.01.2026 19:42:01

Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025.12.0, an actor who does not have permission to view favorites or clips can can export the posts and view the contents. Version 20...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 05.05.2025 18:38:36
  • Zuletzt bearbeitet 03.09.2025 18:29:40

Misskey is an open source, federated social media platform. Starting in version 12.31.0 and prior to version 2025.4.1, missing validation in `Mk:api` allows malicious AiScript code to access additional endpoints that it isn't designed to have access ...

  • EPSS 0.21%
  • Veröffentlicht 05.05.2025 18:35:37
  • Zuletzt bearbeitet 03.09.2025 18:47:53

Misskey is an open source, federated social media platform. Starting in version 12.0.0 and prior to version 2025.4.1, due to an oversight in the validation performed in `UrlPreviewService` and `MkUrlPreview`, it is possible for an attacker to inject ...

  • EPSS 0.05%
  • Veröffentlicht 10.03.2025 18:13:45
  • Zuletzt bearbeitet 26.11.2025 16:24:21

Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate the relation between the `id` and `url` fields of ActivityPub objects. An attacker can forge an object where they claim authority i...

  • EPSS 0.04%
  • Veröffentlicht 11.02.2025 16:15:51
  • Zuletzt bearbeitet 26.11.2025 16:32:39

Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, due to a lack of CSRF protection and the lack of proper security attributes in the authentication cookies of Bull's dashbo...

  • EPSS 0.33%
  • Veröffentlicht 11.02.2025 16:15:51
  • Zuletzt bearbeitet 20.02.2025 15:48:37

Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, a login token named `token` is stored in a cookie for authentication purposes in Bull Dashboard, but this remains undelete...