Misskey

Misskey

24 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 18.12.2024 20:15:23
  • Zuletzt bearbeitet 26.11.2025 16:25:19

Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService.signedGet` and `HttpRequestService.getActivityJson` allows an attacker to create fake user profiles and forged notes. The spoofed...

  • EPSS 0.18%
  • Veröffentlicht 18.12.2024 20:15:23
  • Zuletzt bearbeitet 26.11.2025 15:48:13

Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService.signedGet` allows an attacker to create fake user profiles that appear to be from a different instance than the one where they ac...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 03.06.2024 16:15:08
  • Zuletzt bearbeitet 25.11.2025 20:37:04

Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSON structures of incoming signed ActivityPub activity objects before processing them, allowing threat actors to spoof the contents ...

  • EPSS 0.21%
  • Veröffentlicht 19.02.2024 20:15:46
  • Zuletzt bearbeitet 05.02.2025 22:36:30

Misskey is an open source, decentralized social media platform with ActivityPub support. Prior to version 2024.2.0, when fetching remote Activity Streams objects, Misskey doesn't check that the response from the remote server has a `Content-Type` hea...

  • EPSS 0.15%
  • Veröffentlicht 29.12.2023 18:15:39
  • Zuletzt bearbeitet 21.11.2024 08:39:15

Misskey is an open source, decentralized social media platform. Third-party applications may be able to access some endpoints or Websocket APIs that are incorrectly specified as [kind](https://github.com/misskey-dev/misskey/blob/406b4bdbe79b5b0b68fcd...

  • EPSS 0.14%
  • Veröffentlicht 29.11.2023 19:15:07
  • Zuletzt bearbeitet 21.11.2024 08:32:46

Misskey is an open source, decentralized social media platform. Misskey's missing signature validation allows arbitrary users to impersonate any remote user. This issue has been patched in version 2023.11.1-beta.1.

  • EPSS 0.21%
  • Veröffentlicht 04.10.2023 21:15:10
  • Zuletzt bearbeitet 21.11.2024 08:24:47

Misskey is an open source, decentralized social media platform. Prior to version 2023.9.0, by editing the URL, a user can bypass the authentication of the Bull dashboard, which is the job queue management UI, and access it. Version 2023.9.0 contains ...

  • EPSS 0.63%
  • Veröffentlicht 22.02.2023 20:15:12
  • Zuletzt bearbeitet 21.11.2024 07:48:26

Misskey is an open source, decentralized social media platform. In versions prior to 13.3.3 SQL injection is possible due to insufficient parameter validation in the note search API by tag (notes/search-by-tag). This has been fixed in version 13.3.3....

  • EPSS 0.54%
  • Veröffentlicht 22.02.2023 20:15:12
  • Zuletzt bearbeitet 21.11.2024 07:48:26

Misskey is an open source, decentralized social media platform. In versions prior to 13.3.2 the URL preview function is subject to a cross site scripting vulnerability due to insufficient URL validation. Arbitrary JavaScript is executed when a malici...

  • EPSS 0.51%
  • Veröffentlicht 22.02.2023 20:15:12
  • Zuletzt bearbeitet 21.11.2024 07:48:26

Misskey is an open source, decentralized social media platform. Due to insufficient validation of the redirect URL during `miauth` authentication in Misskey, arbitrary JavaScript can be executed when a user allows the link. All versions below 13.3.1 ...