Misskey

Misskey

24 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.08%
  • Veröffentlicht 15.12.2025 23:18:37
  • Zuletzt bearbeitet 06.01.2026 19:41:47

Misskey is an open source, federated social media platform. Attackers who use an untrusted reverse proxy or not using a reverse proxy at all can bypass IP rate limiting by adding a forged X-Forwarded-For header. Starting with version 2025.9.1, an opt...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 15.12.2025 23:09:57
  • Zuletzt bearbeitet 06.01.2026 19:42:01

Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025.12.0, an actor who does not have permission to view favorites or clips can can export the posts and view the contents. Version 20...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 05.05.2025 18:38:36
  • Zuletzt bearbeitet 03.09.2025 18:29:40

Misskey is an open source, federated social media platform. Starting in version 12.31.0 and prior to version 2025.4.1, missing validation in `Mk:api` allows malicious AiScript code to access additional endpoints that it isn't designed to have access ...

  • EPSS 0.21%
  • Veröffentlicht 05.05.2025 18:35:37
  • Zuletzt bearbeitet 03.09.2025 18:47:53

Misskey is an open source, federated social media platform. Starting in version 12.0.0 and prior to version 2025.4.1, due to an oversight in the validation performed in `UrlPreviewService` and `MkUrlPreview`, it is possible for an attacker to inject ...

  • EPSS 0.05%
  • Veröffentlicht 10.03.2025 18:13:45
  • Zuletzt bearbeitet 26.11.2025 16:24:21

Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate the relation between the `id` and `url` fields of ActivityPub objects. An attacker can forge an object where they claim authority i...

  • EPSS 0.02%
  • Veröffentlicht 11.02.2025 16:15:51
  • Zuletzt bearbeitet 26.11.2025 16:32:39

Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, due to a lack of CSRF protection and the lack of proper security attributes in the authentication cookies of Bull's dashbo...

  • EPSS 0.13%
  • Veröffentlicht 11.02.2025 16:15:51
  • Zuletzt bearbeitet 20.02.2025 15:48:37

Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, a login token named `token` is stored in a cookie for authentication purposes in Bull Dashboard, but this remains undelete...

  • EPSS 0.13%
  • Veröffentlicht 18.12.2024 20:15:23
  • Zuletzt bearbeitet 26.11.2025 16:33:39

Misskey is an open source, federated social media platform. Some APIs using `HttpRequestService` do not properly check the target host. This vulnerability allows an attacker to send POST or GET requests to the internal server, which may result in a S...

  • EPSS 0.28%
  • Veröffentlicht 18.12.2024 20:15:23
  • Zuletzt bearbeitet 26.11.2025 16:34:54

Misskey is an open source, federated social media platform.In affected versions missing validation in `NoteCreateService.insertNote`, `ApPersonService.createPerson`, and `ApPersonService.updatePerson` allows an attacker to control the target of any "...

  • EPSS 0.37%
  • Veröffentlicht 18.12.2024 20:15:23
  • Zuletzt bearbeitet 26.11.2025 16:34:36

Misskey is an open source, federated social media platform. In affected versions missing validation in `ApInboxService.update` allows an attacker to modify the result of polls belonging to another user. No authentication is required, except for a val...