CVE-2025-66482
- EPSS 0.08%
- Veröffentlicht 15.12.2025 23:18:37
- Zuletzt bearbeitet 06.01.2026 19:41:47
Misskey is an open source, federated social media platform. Attackers who use an untrusted reverse proxy or not using a reverse proxy at all can bypass IP rate limiting by adding a forged X-Forwarded-For header. Starting with version 2025.9.1, an opt...
CVE-2025-66402
- EPSS 0.04%
- Veröffentlicht 15.12.2025 23:09:57
- Zuletzt bearbeitet 06.01.2026 19:42:01
Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025.12.0, an actor who does not have permission to view favorites or clips can can export the posts and view the contents. Version 20...
CVE-2025-46559
- EPSS 0.15%
- Veröffentlicht 05.05.2025 18:38:36
- Zuletzt bearbeitet 03.09.2025 18:29:40
Misskey is an open source, federated social media platform. Starting in version 12.31.0 and prior to version 2025.4.1, missing validation in `Mk:api` allows malicious AiScript code to access additional endpoints that it isn't designed to have access ...
CVE-2025-46340
- EPSS 0.21%
- Veröffentlicht 05.05.2025 18:35:37
- Zuletzt bearbeitet 03.09.2025 18:47:53
Misskey is an open source, federated social media platform. Starting in version 12.0.0 and prior to version 2025.4.1, due to an oversight in the validation performed in `UrlPreviewService` and `MkUrlPreview`, it is possible for an attacker to inject ...
CVE-2025-25306
- EPSS 0.05%
- Veröffentlicht 10.03.2025 18:13:45
- Zuletzt bearbeitet 26.11.2025 16:24:21
Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate the relation between the `id` and `url` fields of ActivityPub objects. An attacker can forge an object where they claim authority i...
CVE-2025-24897
- EPSS 0.02%
- Veröffentlicht 11.02.2025 16:15:51
- Zuletzt bearbeitet 26.11.2025 16:32:39
Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, due to a lack of CSRF protection and the lack of proper security attributes in the authentication cookies of Bull's dashbo...
CVE-2025-24896
- EPSS 0.13%
- Veröffentlicht 11.02.2025 16:15:51
- Zuletzt bearbeitet 20.02.2025 15:48:37
Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, a login token named `token` is stored in a cookie for authentication purposes in Bull Dashboard, but this remains undelete...
CVE-2024-52579
- EPSS 0.13%
- Veröffentlicht 18.12.2024 20:15:23
- Zuletzt bearbeitet 26.11.2025 16:33:39
Misskey is an open source, federated social media platform. Some APIs using `HttpRequestService` do not properly check the target host. This vulnerability allows an attacker to send POST or GET requests to the internal server, which may result in a S...
CVE-2024-52593
- EPSS 0.28%
- Veröffentlicht 18.12.2024 20:15:23
- Zuletzt bearbeitet 26.11.2025 16:34:54
Misskey is an open source, federated social media platform.In affected versions missing validation in `NoteCreateService.insertNote`, `ApPersonService.createPerson`, and `ApPersonService.updatePerson` allows an attacker to control the target of any "...
CVE-2024-52592
- EPSS 0.37%
- Veröffentlicht 18.12.2024 20:15:23
- Zuletzt bearbeitet 26.11.2025 16:34:36
Misskey is an open source, federated social media platform. In affected versions missing validation in `ApInboxService.update` allows an attacker to modify the result of polls belonging to another user. No authentication is required, except for a val...