PT-2024-35387 · Misskey · Misskey

Warriordog

·

Published

2024-12-18

·

Updated

2025-11-26

·

CVE-2024-52590

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:N/SA:L
Name of the Vulnerable Software and Affected Versions Misskey versions prior to 2024.11.0-alpha.3
Description The issue concerns missing validation in ApRequestService.signedGet, allowing an attacker to create fake user profiles that appear to be from a different instance. These profiles can be used to impersonate existing users, giving attackers full control to post, renote, or interact like a real account.
Recommendations For versions prior to 2024.11.0-alpha.3, upgrade to version 2024.11.0-alpha.3 or later to resolve the issue. As a temporary workaround, consider restricting interactions with unverified or suspicious user profiles until the upgrade can be applied.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-52590
GHSA-7VGR-P3VC-P4H2

Affected Products

Misskey