JSON-LD Signature Validation Flaw in Misskey Social Media Platform
CVE-2026-46713

9.2CRITICAL

Key Information:

Status
Vendor
CVE Published:
3 August 2026

What is CVE-2026-46713?

The Misskey social media platform, which is open source and federated, has a vulnerability in its JSON-LD signature validation and compaction process. This flaw permits unauthorized activities to be misrepresented as valid, undermining the platform's integrity and user trust. The vulnerability affects versions from 12.37.0 up until 2026.5.4, and has been addressed in the latest release, version 2026.5.4.

Affected Version(s)

misskey >= 12.37.0, < 2026.5.4

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.