Vulnerabilities in misskey-dev
35 resultsVexday analysis
Misskey-dev apresenta 30 vulnerabilidades catalogadas, das quais 4 são críticas, sem registros de exploração ativa conhecida até o momento. A fraqueza dominante é validação inadequada de entrada (CWE-20), padrão que sugere falhas sistemáticas em sanitização de dados; o ritmo recente de 2 divulgações nos últimos 90 dias indica que a superfície de risco permanece em evolução.
CVE-2024-52590HIGHMissing validation allows spoofed profiles in MisskeyEPSS 0.4%CVE-2025-66482MEDIUMMisskey has a login rate limit bypass via spoofed X-Forwarded-For headerEPSS 0.3%CVE-2024-49363HIGHUncontrolled Recursion and Asymmetric Resource Consumption (Amplification) in media/file proxy in MisskeyEPSS 0.3%CVE-2024-52591HIGHMissing validation allows spoofed profiles and notes in MisskeyEPSS 0.3%CVE-2025-66402HIGHmisskey.js's export data contains private post dataEPSS 0.3%CVE-2024-52592MEDIUMMissing validation allows spoofed poll updates in MisskeyEPSS 0.3%CVE-2026-47746HIGHMisskey: JSON-LD signature validation + compaction is vulnerable to timing attacksEPSS 0.3%CVE-2026-46713CRITICALMisskey: JSON-LD signature validation + compaction may lead to improper activity handlingEPSS 0.3%CVE-2026-28433LOWMisskey lacks resource ownership validationEPSS 0.3%CVE-2025-46553LOW@misskey-dev/summaly Redirect Filter BypassEPSS 0.2%CVE-2025-46340HIGHMisskey CSS Style Injection Vulnerability In `MkUrlPreview`EPSS 0.2%CVE-2026-28432HIGHHTTP signature verification can be bypassedEPSS 0.2%CVE-2024-52579MEDIUMServer-Side Request Forgery vulnerability in various APIs in MisskeyEPSS 0.2%CVE-2025-25306CRITICALMisskey's Incomplete Patch of CVE-2024-52591 Leads to Forgery of Federated NotesEPSS 0.2%CVE-2025-24897HIGHMisskey CSRF vulnerability due to insecure configuration of authentication cookie attributesEPSS 0.1%