Impact
Misskey is an open‑source federated social media platform that supports custom themes. The vulnerability exists in the theme compiler and allows an attacker to craft a malformed theme that triggers uncontrolled recursion. When the web client processes such a theme the recursion can cause the browser to consume excessive resources, leading to significant slowdown or a crash, which results in a denial of service for users interacting with the client.
Affected Systems
The issue affects misskey-dev’s Misskey platform. All versions starting at 8.63.0 and up to, but not including, 2026.5.4 are vulnerable. The fix is included in release 2026.5.4 and later releases.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not widely exploited yet. An attacker can exploit it by providing a malicious theme to the web client—either by uploading it as an authorized user or by tricking a regular user into loading a theme file—so the risk is contingent on the attacker’s ability to influence theme selection.
OpenCVE Enrichment