CSS Injection Vulnerability in Misskey Open Source Social Media Platform
CVE-2025-46340

7.2HIGH

Key Information:

Status
Vendor
CVE Published:
5 May 2025

What is CVE-2025-46340?

The Misskey social media platform contains a vulnerability due to improper validation in the UrlPreviewService and MkUrlPreview components. This flaw enables attackers to inject arbitrary CSS into the MkUrlPreview, which can be exploited to de-anonymize users and conduct further attacks. The vulnerable versions, prior to 2025.4.1, fail to sanitize input effectively, allowing crafted URLs to apply deceptive styles. Attackers can manipulate the display, potentially tricking users into divulging sensitive information through misleading error messages. A patch has been released in version 2025.4.1.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

misskey >= 12.0.0, < 2025.4.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.