Impact
Misskey’s JSON‑LD signature validation and compaction logic does not fully validate incoming activity payloads, allowing an attacker to forge JSON‑LD activities that the server accepts as authentic. The flaw is defined as CWE‑347 and enables unauthorized actions and user impersonation, potentially leading to the execution of malicious commands or the spread of misinformation through the federated network.
Affected Systems
All releases of Misskey from version 12.37.0 up to, but not including, 2026.5.4 are affected. The vendor is misskey‑dev and the product is the Misskey social‑media platform. Only these versions contain the vulnerable logic; version 2026.5.4 and newer include the fix.
Risk and Exploitability
The CVSS score of 9.2 signals a high‑risk vulnerability. Because the flaw is triggered by an incoming federated activity, the likely attack vector is remote and requires no local privileges. EPSS is not available and the issue is not listed in CISA’s KEV catalog, yet the high CVSS and the nature of the attack craft a scenario where compromised instances could serve as sources of spoofed activities, facilitating large‑scale social engineering or misinformation campaigns.
OpenCVE Enrichment