← volver
CVE-2025-46553

@misskey-dev/summaly Redirect Filter Bypass

CVSS 2.1 LOWEPSS 0.2%CWE-601CWE-665CWE-669CWE-693
@misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1, a logic error in the main `summaly` function causes the `allowRedirects` option to never be passed to any plugins, and as a result, isn't enforced. Misskey will follow redirects, despite explicitly requesting not to. Version 5.2.1 contains a patch for the issue.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:P
Productos afectados
misskey-dev · summaly

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →