Description
Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD signature validation and compaction process that allows spoofed activities to be accepted as valid. This issue has been fixed in version 2026.5.4.
Published: 2026-08-03
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Misskey’s JSON‑LD signature validation and compaction logic does not fully validate incoming activity payloads, allowing an attacker to forge JSON‑LD activities that the server accepts as authentic. The flaw is defined as CWE‑347 and enables unauthorized actions and user impersonation, potentially leading to the execution of malicious commands or the spread of misinformation through the federated network.

Affected Systems

All releases of Misskey from version 12.37.0 up to, but not including, 2026.5.4 are affected. The vendor is misskey‑dev and the product is the Misskey social‑media platform. Only these versions contain the vulnerable logic; version 2026.5.4 and newer include the fix.

Risk and Exploitability

The CVSS score of 9.2 signals a high‑risk vulnerability. Because the flaw is triggered by an incoming federated activity, the likely attack vector is remote and requires no local privileges. EPSS is not available and the issue is not listed in CISA’s KEV catalog, yet the high CVSS and the nature of the attack craft a scenario where compromised instances could serve as sources of spoofed activities, facilitating large‑scale social engineering or misinformation campaigns.

Generated by OpenCVE AI on August 4, 2026 at 20:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Misskey installation to version 2026.5.4 or newer, which contains the JSON‑LD validation fix.
  • If an upgrade cannot be performed immediately, block or whitelist federation traffic from untrusted or unknown peers to prevent the ingestion of forged activities until the patch is applied.
  • Enable logging and actively monitor for anomalous activity patterns, and block IP addresses or accounts that produce forged actions as a temporary countermeasure.

Generated by OpenCVE AI on August 4, 2026 at 20:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Misskey
Misskey misskey
Vendors & Products Misskey
Misskey misskey

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD signature validation and compaction process that allows spoofed activities to be accepted as valid. This issue has been fixed in version 2026.5.4.
Title Misskey: JSON-LD signature validation + compaction may lead to improper activity handling
Weaknesses CWE-347
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-04T15:44:53.013Z

Reserved: 2026-05-15T23:26:58.309Z

Link: CVE-2026-46713

cve-icon Vulnrichment

Updated: 2026-08-04T15:44:31.112Z

cve-icon NVD

Status : Received

Published: 2026-08-03T22:16:49.017

Modified: 2026-08-04T17:16:54.770

Link: CVE-2026-46713

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T09:45:06Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature