Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate the relation between the `id` and `url` fields of ActivityPub objects. An attacker can forge an object where they claim authority in the `url` field even if the specific ActivityPub object type require authority in the `id` field. Version 2025.2.1 addresses the issue.
In the ActivityPub protocol, authority over an object should be established based on the `id` field. The patch for CVE-2024-52591 did not sufficiently validate the relationship between the `id` and `url` fields. An attacker can craft an ActivityPub object in which they declare authority using the `url` field, thereby bypassing verification based on the `id` field. This applies to ActivityPub object types that require authority establishment via the `id` field.
A remote attacker, without authentication, can impersonate another server or user in the federated network, leading to unauthorized modification of content or data (high impact on integrity) and limited information disclosure.
Misskey should be updated to version 2025.2.1, which addresses this vulnerability. Patch details and instructions are available in the official GitHub repository at the address indicated in the references.
Misskey — all versions before 2025.2.1 (including versions with an incomplete CVE-2024-52591 patch)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:NMisskey
APPMisskey< 2025.2.1
Related vulnerabilities
Niewystarczająca weryfikacja uprawnień w Misskey — nieautoryzowany dostęp do danych
Misskey: nieprawidłowa autoryzacja API umożliwia wyciek danych i nieautoryzowane operacje
Misskey: brak weryfikacji podpisu umożliwia podszywanie się pod użytkowników
Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vu...
Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to ve...