PT-2024-35387 · Misskey · Misskey
Warriordog
·
Published
2024-12-18
·
Updated
2025-11-26
·
CVE-2024-52590
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:N/SA:L |
Name of the Vulnerable Software and Affected Versions
Misskey versions prior to 2024.11.0-alpha.3
Description
The issue concerns missing validation in
ApRequestService.signedGet, allowing an attacker to create fake user profiles that appear to be from a different instance. These profiles can be used to impersonate existing users, giving attackers full control to post, renote, or interact like a real account.Recommendations
For versions prior to 2024.11.0-alpha.3, upgrade to version 2024.11.0-alpha.3 or later to resolve the issue. As a temporary workaround, consider restricting interactions with unverified or suspicious user profiles until the upgrade can be applied.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misskey