Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

misskey — Vulnerabilities & Security Advisories 35

All 35 CVE vulnerabilities found in misskey, with AI-generated Chinese analysis, references, and POCs.

This page provides vulnerability aggregation data for Misskey, an open-source social media platform developed by the Misskey project, categorized under general software weakness types. It collects publicly disclosed security issues ranging from critical remote code execution flaws to minor information disclosure bugs, covering incidents reported between 2019 and 2024. Users can utilize this resource to track the Misskey vendor's advisory history, understand the prevalence and impact of specific weakness classes within the application, and look up the product's complete vulnerability timeline. The information is compiled from various security databases and official announcements to provide a comprehensive overview of the software's security posture. This aggregated view helps developers and administrators assess risk levels, prioritize patches, and maintain the integrity of their Misskey instances. By centralizing these details, the page simplifies the process of monitoring security updates and responding to emerging threats effectively. The data reflects both known vulnerabilities and those addressed in recent patches, ensuring that stakeholders have access to current and historical context. This approach supports informed decision-making regarding system upgrades and security configurations. Readers are encouraged to cross-reference this information with official project channels for the most accurate and timely updates. The summary does not include specific identifiers but focuses on the nature and scope of the reported issues. This documentation serves as a foundational reference for anyone responsible for the deployment and maintenance of Misskey environments.

Vendor: Misskey

CVE IDTitleCVSSSeverityPublished
CVE-2026-46714 Misskey: Denial of Service via Uncontrolled Recursion in Theme Compilation CWE-674 5.1 Medium2026-08-03
CVE-2026-47746 Misskey: JSON-LD signature validation + compaction is vulnerable to timing attacks CWE-367 8.9 High2026-08-03
CVE-2026-46713 Misskey: JSON-LD signature validation + compaction may lead to improper activity handling CWE-347 9.2 Critical2026-08-03
CVE-2026-46712 Misskey: Lack of proper permission checks in Direct Messaging feature CWE-639 2.3 Low2026-08-03
CVE-2026-48115 Misskey: Improper Authorization in the Announcements API CWE-285 6.3 Medium2026-08-03
CVE-2026-57574 Misskey: TOTP tokens can be reused CWE-294--2026-07-10
CVE-2026-57575 Misskey: SSRF bypass in URL Preview CWE-918--2026-07-10
CVE-2026-28433 Misskey lacks resource ownership validation CWE-639 7.1AIHighAI2026-03-09
CVE-2026-28432 HTTP signature verification can be bypassed CWE-347 7.5AIHighAI2026-03-09
CVE-2026-28431 Misskey lacks proper authorization checks and input validation CWE-285 5.9AIMediumAI2026-03-09
CVE-2025-66482 Misskey has a login rate limit bypass via spoofed X-Forwarded-For header CWE-307 5.3AIMediumAI2025-12-15
CVE-2025-66402 misskey.js's export data contains private post data CWE-862 5.3AIMediumAI2025-12-15
CVE-2025-46559 Misskey Directory Traversal Vulnerability in AiScript via `Mk:api` CWE-22 5.4 Medium2025-05-05
CVE-2025-46340 Misskey CSS Style Injection Vulnerability In `MkUrlPreview` CWE-20 7.2 High2025-05-05
CVE-2025-25306 Misskey's Incomplete Patch of CVE-2024-52591 Leads to Forgery of Federated Notes CWE-346 9.3 Critical2025-03-10
CVE-2025-24897 Misskey CSRF vulnerability due to insecure configuration of authentication cookie attributes CWE-352 8.2 High2025-02-11
CVE-2025-24896 Misskey allows token to remain valid in cookie after signing out CWE-613 8.1 High2025-02-11
CVE-2024-49363 Uncontrolled Recursion and Asymmetric Resource Consumption (Amplification) in media/file proxy in Misskey CWE-405 7.4 High2024-12-18
CVE-2024-52579 Server-Side Request Forgery vulnerability in various APIs in Misskey CWE-918 6.4 Medium2024-12-18
CVE-2024-52590 Missing validation allows spoofed profiles in Misskey CWE-20 8.8 -2024-12-18
CVE-2024-52591 Missing validation allows spoofed profiles and notes in Misskey CWE-20 8.1 -2024-12-18
CVE-2024-52592 Missing validation allows spoofed poll updates in Misskey CWE-20 5.3 -2024-12-18
CVE-2024-52593 Missing validation allows spoofed "origin" links in Misskey CWE-20 5.4 -2024-12-18
CVE-2024-32983 Misskey allows the impersonation and takeover of remote accounts with unnormalized signed activities CWE-863 8.2 High2024-06-03
CVE-2024-25636 Lack of media type verification of Activity Streams objects allows impersonation and takeover of remote accounts CWE-434 7.1 High2024-02-19
CVE-2023-52139 Misskey vulnerable to improper authorization when accessing with third-party application CWE-285 9.1 Critical2023-12-29
CVE-2023-49079 Misskey's missing signature validation allows arbitrary users to impersonate any remote user. CWE-347 9.3 Critical2023-11-29
CVE-2023-43793 Misskey allows users to bypass authentication of Bull dashboard CWE-287 7.5 High2023-10-04
CVE-2023-24810 Cross site scripting (XSS) vulnerability using authentication callback in Misskey CWE-79 7.1 High2023-02-22
CVE-2023-24811 Cross site scripting (XSS) vulnerability using url preview in Misskey CWE-79 7.1 High2023-02-22

All 35 known CVE vulnerabilities affecting misskey with full Chinese analysis, references, and POCs where available.