Data Import Vulnerability in Misskey Social Media Platform
CVE-2026-28433

2.3LOW

Key Information:

Status
Vendor
CVE Published:
9 March 2026

What is CVE-2026-28433?

The Misskey platform, an open-source federated social media service, has a data import issue present in versions 10.93.0 and later, specifically targeting earlier releases than 2026.3.1. This vulnerability arises from the absence of effective ownership validation processes, allowing users to potentially import data belonging to others. While the exploitation of this flaw may seem limited as attackers need specific data IDs to carry out their actions, it raises concerns about user privacy and data integrity within the platform. Immediate updates to version 2026.3.1 or later are essential for securing the affected systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

misskey >= 10.93.0, < 2026.3.1

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.