← Back

Misskey

misskey

28 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Misskey
misskey
Summaly
summaly

CVEs (28)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Misskey
1Misskey
Jun 17, 2026
Oct 4, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Misskey is an open source, decentralized social media platform. Prior to version 2023.9.0, by editing the URL, a user can bypass the authentication of the Bull dashboard, which is the job queue management UI, and access...Show more
Misskey is an open source, decentralized social media platform. Prior to version 2023.9.0, by editing the URL, a user can bypass the authentication of the Bull dashboard, which is the job queue management UI, and access it. Version 2023.9.0 contains a fix. There are no known workarounds.Show less
1Misskey
1Misskey
Jun 17, 2026
Feb 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Misskey is an open source, decentralized social media platform. In versions prior to 13.3.3 SQL injection is possible due to insufficient parameter validation in the note search API by tag (notes/search-by-tag). This has...Show more
Misskey is an open source, decentralized social media platform. In versions prior to 13.3.3 SQL injection is possible due to insufficient parameter validation in the note search API by tag (notes/search-by-tag). This has been fixed in version 13.3.3. Users are advised to upgrade. Users unable to upgrade should block access to the `api/notes/search-by-tag` endpoint.Show less
1Misskey
1Misskey
Jun 17, 2026
Feb 22, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Misskey is an open source, decentralized social media platform. In versions prior to 13.3.2 the URL preview function is subject to a cross site scripting vulnerability due to insufficient URL validation. Arbitrary JavaSc...Show more
Misskey is an open source, decentralized social media platform. In versions prior to 13.3.2 the URL preview function is subject to a cross site scripting vulnerability due to insufficient URL validation. Arbitrary JavaScript is executed when a malicious URL is loaded in the `View in Player` or `View in Window` preview. This has been fixed in version 13.3.2. Users are advised to upgrade. Users unable to upgrade should avoid usage of the `View in Player` or `View in Window` functions. Show less
1Misskey
1Misskey
Jun 17, 2026
Feb 22, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Misskey is an open source, decentralized social media platform. Due to insufficient validation of the redirect URL during `miauth` authentication in Misskey, arbitrary JavaScript can be executed when a user allows the li...Show more
Misskey is an open source, decentralized social media platform. Due to insufficient validation of the redirect URL during `miauth` authentication in Misskey, arbitrary JavaScript can be executed when a user allows the link. All versions below 13.3.1 (including 12.x) are affected. This has been fixed in version 13.3.1. Users are advised to upgrade. Users unable to upgrade should not allow authentication of untrusted apps.Show less
1Misskey
1Misskey
Jun 17, 2026
Feb 22, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Misskey is an open source, decentralized social media platform. In versions prior to 13.5.0 the link to the instance to the sender that appears when viewing a user or note received through ActivityPub is not properly val...Show more
Misskey is an open source, decentralized social media platform. In versions prior to 13.5.0 the link to the instance to the sender that appears when viewing a user or note received through ActivityPub is not properly validated, so by inserting a URL with a javascript scheme an attacker may execute JavaScript code in the context of the recipient. This issue has been fixed in version 13.5.0. Users are advised to upgrade. Users unable to upgrade should not "view on remote" for untrusted instances.Show less
1Misskey
1Misskey
Jun 17, 2026
Sep 7, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Misskey is an open source, decentralized microblogging platform. In affected versions a Server-Side Request Forgery vulnerability exists in "Upload from URL" and remote attachment handling. This could result in the discl...Show more
Misskey is an open source, decentralized microblogging platform. In affected versions a Server-Side Request Forgery vulnerability exists in "Upload from URL" and remote attachment handling. This could result in the disclosure of non-public information within the internal network. This has been fixed in 12.90.0. However, if you are using a proxy, you will need to take additional measures. As a workaround this exploit may be avoided by appropriately restricting access to private networks from the host where the application is running.Show less
1Misskey
1Misskey
Jun 17, 2026
Aug 27, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Misskey is a decentralized microblogging platform. In versions of Misskey prior to 12.51.0, malicious actors can use the web client built-in dialog to display a malicious string, leading to cross-site scripting (XSS). XS...Show more
Misskey is a decentralized microblogging platform. In versions of Misskey prior to 12.51.0, malicious actors can use the web client built-in dialog to display a malicious string, leading to cross-site scripting (XSS). XSS could compromise the API request token. This issue has been fixed in version 12.51.0. There are no known workarounds aside from upgrading.Show less
1Misskey
1Misskey
Jun 17, 2026
Jul 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Misskey before 10.102.4 allows hijacking a user's token.