Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7668 | Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate the relation between the `id` and `url` fields of ActivityPub objects. An attacker can forge an object where they claim authority in the `url` field even if the specific ActivityPub object type require authority in the `id` field. Version 2025.2.1 addresses the issue. |
Wed, 26 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Misskey
Misskey misskey |
|
| CPEs | cpe:2.3:a:misskey:misskey:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Misskey
Misskey misskey |
Thu, 13 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Mar 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate the relation between the `id` and `url` fields of ActivityPub objects. An attacker can forge an object where they claim authority in the `url` field even if the specific ActivityPub object type require authority in the `id` field. Version 2025.2.1 addresses the issue. | |
| Title | Misskey's Incomplete Patch of CVE-2024-52591 Leads to Forgery of Federated Notes | |
| Weaknesses | CWE-1025 CWE-346 CWE-441 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-12T19:49:47.787Z
Reserved: 2025-02-06T17:13:33.124Z
Link: CVE-2025-25306
Updated: 2025-03-10T19:11:35.322Z
Status : Analyzed
Published: 2025-03-10T19:15:40.230
Modified: 2025-11-26T16:24:21.260
Link: CVE-2025-25306
No data.
OpenCVE Enrichment
No data.
EUVD