CSS Injection Vulnerability in Misskey Open Source Social Media Platform
CVE-2025-46340
What is CVE-2025-46340?
The Misskey social media platform contains a vulnerability due to improper validation in the UrlPreviewService and MkUrlPreview components. This flaw enables attackers to inject arbitrary CSS into the MkUrlPreview, which can be exploited to de-anonymize users and conduct further attacks. The vulnerable versions, prior to 2025.4.1, fail to sanitize input effectively, allowing crafted URLs to apply deceptive styles. Attackers can manipulate the display, potentially tricking users into divulging sensitive information through misleading error messages. A patch has been released in version 2025.4.1.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
misskey >= 12.0.0, < 2025.4.1
