Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13413 | @misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1, a logic error in the main `summaly` function causes the `allowRedirects` option to never be passed to any plugins, and as a result, isn't enforced. Misskey will follow redirects, despite explicitly requesting not to. Version 5.2.1 contains a patch for the issue. |
Github GHSA |
GHSA-7899-w6c4-vqc4 | @misskey-dev/summaly Redirect Filter Bypass |
Mon, 01 Dec 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Misskey summaly
|
|
| CPEs | cpe:2.3:a:misskey:summaly:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Misskey misskey
|
Misskey summaly
|
Wed, 03 Sep 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Misskey
Misskey misskey |
|
| CPEs | cpe:2.3:a:misskey:misskey:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Misskey
Misskey misskey |
|
| Metrics |
cvssV3_1
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 05 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 May 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | @misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1, a logic error in the main `summaly` function causes the `allowRedirects` option to never be passed to any plugins, and as a result, isn't enforced. Misskey will follow redirects, despite explicitly requesting not to. Version 5.2.1 contains a patch for the issue. | |
| Title | @misskey-dev/summaly Redirect Filter Bypass | |
| Weaknesses | CWE-601 CWE-665 CWE-669 CWE-693 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-05T18:50:42.815Z
Reserved: 2025-04-24T21:10:48.173Z
Link: CVE-2025-46553
Updated: 2025-05-05T18:50:26.929Z
Status : Analyzed
Published: 2025-05-05T19:15:56.763
Modified: 2025-12-01T13:49:38.397
Link: CVE-2025-46553
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA