CRITICAL🇵🇱 Wersja polska

CVE-2025-25306

CVSS 9.3v3.1pub. 2025-03-10upd. 2025-11-26

Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate the relation between the `id` and `url` fields of ActivityPub objects. An attacker can forge an object where they claim authority in the `url` field even if the specific ActivityPub object type require authority in the `id` field. Version 2025.2.1 addresses the issue.

🤖 AI Analysis
How it works

In the ActivityPub protocol, authority over an object should be established based on the `id` field. The patch for CVE-2024-52591 did not sufficiently validate the relationship between the `id` and `url` fields. An attacker can craft an ActivityPub object in which they declare authority using the `url` field, thereby bypassing verification based on the `id` field. This applies to ActivityPub object types that require authority establishment via the `id` field.

Impact

A remote attacker, without authentication, can impersonate another server or user in the federated network, leading to unauthorized modification of content or data (high impact on integrity) and limited information disclosure.

Mitigation & patch

Misskey should be updated to version 2025.2.1, which addresses this vulnerability. Patch details and instructions are available in the official GitHub repository at the address indicated in the references.

Who is affected

Misskey — all versions before 2025.2.1 (including versions with an incomplete CVE-2024-52591 patch)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N
  • Misskey

    APP
    Misskey
    < 2025.2.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-28431CRITICAL9.2PL ✓same product

Niewystarczająca weryfikacja uprawnień w Misskey — nieautoryzowany dostęp do danych

CVE-2023-52139CRITICAL9.0PL ✓same product

Misskey: nieprawidłowa autoryzacja API umożliwia wyciek danych i nieautoryzowane operacje

CVE-2023-49079CRITICAL9.3PL ✓same product

Misskey: brak weryfikacji podpisu umożliwia podszywanie się pod użytkowników

CVE-2026-28432HIGH7.1same product

Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vu...

CVE-2025-66402HIGH7.1same product

Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to ve...