PT-2024-35388 · Misskey · Misskey

Warriordog

·

Published

2024-12-18

·

Updated

2025-03-11

·

CVE-2024-52591

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Misskey versions prior to 2024.11.0-alpha.3
Description Misskey is an open source, federated social media platform. In affected versions, missing validation in ApRequestService.signedGet and HttpRequestService.getActivityJson allows an attacker to create fake user profiles and forged notes. The spoofed users will appear to be from a different instance than the one where they actually exist, and the forged notes will appear to be posted by a different user. Vulnerable Misskey instances will accept the spoofed objects as valid, allowing an attacker to impersonate other users and instances. The attacker retains full control of the spoofed user / note and can interact like a real account.
Recommendations To resolve the issue, update to version 2024.11.0-alpha.3 or later. As a temporary workaround, consider restricting interactions with unverified user profiles and notes until the update is applied. There are no known workarounds for this vulnerability, so upgrading to the fixed version is the recommended course of action.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-52591
GHSA-M2GQ-69FP-6HV4

Affected Products

Misskey