Misskey is an open source, decentralized social media platform. Misskey's missing signature validation allows arbitrary users to impersonate any remote user. This issue has been patched in version 2023.11.1-beta.1.
Misskey as a decentralized social platform uses a federation protocol in which remote user identities should be verified using cryptographic signatures. Due to the lack of this verification (CWE-347 – Improper Verification of Cryptographic Signature), an attacker can send messages or activities signed on behalf of any remote user without possessing the appropriate private key. The system does not validate the signature, accepting false requests as authentic.
An attacker can effectively impersonate any remote federated user, falsifying their identity and actions on the network, leading to high data integrity violation and partial information disclosure.
Misskey should be updated to version 2023.11.1-beta.1 or newer, which introduces proper cryptographic signature verification. Details available in the vendor references (GitHub Security Advisory GHSA-3f39-6537-3cgc).
Misskey in all versions prior to 2023.11.1-beta.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:NMisskey
APPMisskey< 2023.11.1
Related vulnerabilities
Niewystarczająca weryfikacja uprawnień w Misskey — nieautoryzowany dostęp do danych
Misskey: niewystarczająca walidacja obiektów ActivityPub (bypass patcha CVE-2024-52591)
Misskey: nieprawidłowa autoryzacja API umożliwia wyciek danych i nieautoryzowane operacje
Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vu...
Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to ve...