Impact
Misskey versions 2025.3.2 through the release before 2026.5.4 have a missing permission check that allows an attacker to retrieve certain data points from the Direct Messaging module regardless of the user’s account permissions. The flaw enables the disclosure of private message content and related metadata, breaching confidentiality. The weakness is formally categorized as CWE‑639—Authorization Bypass Through User‑Controlled Key. The vulnerability is not limited to federated instances; it persists whether or not federation is enabled, meaning that any user with access to the application can potentially exploit the flaw.
Affected Systems
The affected product is the open‑source Misskey platform developed by misskey‑dev. All releases from version 2025.3.2 up to, but excluding, 2026.5.4 are impacted. The only unaffected content are notes created with the “specified” (formerly “direct”) visibility setting, which is not susceptible to the unchecked access.
Risk and Exploitability
The vulnerability carries a CVSS score of 2.3, indicating low severity. No EPSS value is reported, leaving the likelihood of exploitation uncertain but presumed low. The issue is not listed in the CISA Known Exploited Vulnerabilities catalog. Although the attack vector is not explicitly detailed, it is inferred that any user able to interact with the Direct Messaging API—whether locally or over the network—could read protected message data. The scope of compromise affects confidentiality for all users on the instance, with no direct impact on integrity or availability.
OpenCVE Enrichment