Open Source Social Media Platform Vulnerability in Misskey
CVE-2025-46559

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 May 2025

What is CVE-2025-46559?

Misskey is an open-source, federated social media platform that has a vulnerability due to improper validation in its API. This flaw, present in versions 12.31.0 through 2025.4.1, enables attackers to exploit AiScript code to access unauthorized endpoints by manipulating API requests. Specifically, the vulnerability allows for directory traversal using a prefix of '../', which could lead to unauthorized access to sensitive endpoints such as /files, /url, and /proxy. This security issue has been addressed in version 2025.4.1.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

misskey >= 12.31.0, < 2025.4.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.