Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

misskey-dev — Vulnerabilities & Security Advisories 35

Browse all 35 CVE security advisories affecting misskey-dev. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Misskey-dev is the primary development entity behind Misskey, a widely adopted open-source federated microblogging platform. The software facilitates decentralized social networking, allowing users to post content, follow others, and interact across independent instances within the Fediverse. Historically, security audits have identified twenty-eight Common Vulnerabilities and Exposures (CVEs) associated with the codebase. These flaws predominantly involve cross-site scripting (XSS), remote code execution (RCE), and privilege escalation vulnerabilities, often stemming from insufficient input validation or improper access control mechanisms in server-side components. While no catastrophic data breaches have been publicly confirmed as direct results of these specific CVEs, the recurring nature of these issues highlights challenges in maintaining secure code practices within a rapidly evolving open-source project. Continuous patching and community-driven security reviews remain essential for mitigating these risks and ensuring the integrity of the federated network infrastructure.

Found 34 results / 35 Clear Filters
Top products by misskey-dev: misskey summaly
CVE ID Title CVSS Severity Published
CVE-2026-46714 Misskey: Denial of Service via Uncontrolled Recursion in Theme Compilation — misskey CWE-674 5.1 Medium 2026-08-03
CVE-2026-47746 Misskey: JSON-LD signature validation + compaction is vulnerable to timing attacks — misskey CWE-367 8.9 High 2026-08-03
CVE-2026-46713 Misskey: JSON-LD signature validation + compaction may lead to improper activity handling — misskey CWE-347 9.2 Critical 2026-08-03
CVE-2026-46712 Misskey: Lack of proper permission checks in Direct Messaging feature — misskey CWE-639 2.3 Low 2026-08-03
CVE-2026-48115 Misskey: Improper Authorization in the Announcements API — misskey CWE-285 6.3 Medium 2026-08-03
CVE-2026-57574 Misskey: TOTP tokens can be reused — misskey CWE-294 - - 2026-07-10
CVE-2026-57575 Misskey: SSRF bypass in URL Preview — misskey CWE-918 - - 2026-07-10
CVE-2026-28433 Misskey lacks resource ownership validation — misskey CWE-639 7.1AI High AI 2026-03-09
CVE-2026-28432 HTTP signature verification can be bypassed — misskey CWE-347 7.5AI High AI 2026-03-09
CVE-2026-28431 Misskey lacks proper authorization checks and input validation — misskey CWE-285 5.9AI Medium AI 2026-03-09
CVE-2025-66482 Misskey has a login rate limit bypass via spoofed X-Forwarded-For header — misskey CWE-307 5.3AI Medium AI 2025-12-15
CVE-2025-66402 misskey.js's export data contains private post data — misskey CWE-862 5.3AI Medium AI 2025-12-15
CVE-2025-46559 Misskey Directory Traversal Vulnerability in AiScript via `Mk:api` — misskey CWE-22 5.4 Medium 2025-05-05
CVE-2025-46340 Misskey CSS Style Injection Vulnerability In `MkUrlPreview` — misskey CWE-20 7.2 High 2025-05-05
CVE-2025-25306 Misskey's Incomplete Patch of CVE-2024-52591 Leads to Forgery of Federated Notes — misskey CWE-346 9.3 Critical 2025-03-10
CVE-2025-24897 Misskey CSRF vulnerability due to insecure configuration of authentication cookie attributes — misskey CWE-352 8.2 High 2025-02-11
CVE-2025-24896 Misskey allows token to remain valid in cookie after signing out — misskey CWE-613 8.1 High 2025-02-11
CVE-2024-49363 Uncontrolled Recursion and Asymmetric Resource Consumption (Amplification) in media/file proxy in Misskey — misskey CWE-405 7.4 High 2024-12-18
CVE-2024-52579 Server-Side Request Forgery vulnerability in various APIs in Misskey — misskey CWE-918 6.4 Medium 2024-12-18
CVE-2024-52590 Missing validation allows spoofed profiles in Misskey — misskey CWE-20 8.8 - 2024-12-18
CVE-2024-52591 Missing validation allows spoofed profiles and notes in Misskey — misskey CWE-20 8.1 - 2024-12-18
CVE-2024-52592 Missing validation allows spoofed poll updates in Misskey — misskey CWE-20 5.3 - 2024-12-18
CVE-2024-52593 Missing validation allows spoofed "origin" links in Misskey — misskey CWE-20 5.4 - 2024-12-18
CVE-2024-32983 Misskey allows the impersonation and takeover of remote accounts with unnormalized signed activities — misskey CWE-863 8.2 High 2024-06-03
CVE-2024-25636 Lack of media type verification of Activity Streams objects allows impersonation and takeover of remote accounts — misskey CWE-434 7.1 High 2024-02-19
CVE-2023-52139 Misskey vulnerable to improper authorization when accessing with third-party application — misskey CWE-285 9.1 Critical 2023-12-29
CVE-2023-49079 Misskey's missing signature validation allows arbitrary users to impersonate any remote user. — misskey CWE-347 9.3 Critical 2023-11-29
CVE-2023-43793 Misskey allows users to bypass authentication of Bull dashboard — misskey CWE-287 7.5 High 2023-10-04
CVE-2023-24810 Cross site scripting (XSS) vulnerability using authentication callback in Misskey — misskey CWE-79 7.1 High 2023-02-22
CVE-2023-24811 Cross site scripting (XSS) vulnerability using url preview in Misskey — misskey CWE-79 7.1 High 2023-02-22

This page lists every published CVE security advisory associated with misskey-dev. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.