Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-496g-mmpw-j9x3 | misskey.js's export data contains private post data |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 06 Jan 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:misskey:misskey:*:*:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:-:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta16:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta21:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta22:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta23:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta24:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta25:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta26:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta27:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta28:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta29:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta30:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta31:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta32:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta33:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta34:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta35:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta36:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta37:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta38:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta39:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta40:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta41:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta42:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:beta43:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:rc10:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:rc11:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:rc1:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:rc2:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:rc3:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:rc4:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:rc5:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:rc6:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:rc7:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:rc8:*:*:*:*:*:* cpe:2.3:a:misskey:misskey:13.0.0:rc9:*:*:*:*:*:* |
|
| Metrics |
cvssV3_1
|
Tue, 16 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Misskey
Misskey misskey |
|
| Vendors & Products |
Misskey
Misskey misskey |
Tue, 16 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Dec 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025.12.0, an actor who does not have permission to view favorites or clips can can export the posts and view the contents. Version 2025.12.0 fixes the issue. | |
| Title | misskey.js's export data contains private post data | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-16T15:09:28.546Z
Reserved: 2025-11-28T23:33:56.364Z
Link: CVE-2025-66402
Updated: 2025-12-16T14:37:38.179Z
Status : Analyzed
Published: 2025-12-16T00:16:02.207
Modified: 2026-01-06T19:42:01.183
Link: CVE-2025-66402
No data.
OpenCVE Enrichment
Updated: 2025-12-16T17:11:24Z
Github GHSA