PT-2024-35389 · Misskey · Misskey

Warriordog

·

Published

2024-12-18

·

Updated

2025-11-26

·

CVE-2024-52592

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Misskey versions prior to 2024.11.0-alpha.3
Description Misskey is an open source, federated social media platform. In affected versions, missing validation in ApInboxService.update allows an attacker to modify the result of polls belonging to another user. No authentication is required, except for a valid signature from any actor on any remote instance. Vulnerable Misskey instances will accept spoofed updates for remote polls. Local polls are unaffected.
Recommendations For versions prior to 2024.11.0-alpha.3, update to version 2024.11.0-alpha.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the ApInboxService.update function until a patch is available. Avoid accepting updates for remote polls from untrusted sources until the issue is resolved.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-52592
GHSA-5H8R-GQ97-XV69

Affected Products

Misskey