Description
Misskey is an open source, federated social media platform. IVersions 8.63.0 and later, but prior to 2026.5.4, contain a vulnerability that can cause the Misskey web client to slow down or crash when it applies a malformed theme. This issue has been fixed in version 2026.5.4.
Published: 2026-08-03
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Misskey is an open‑source federated social media platform that supports custom themes. The vulnerability exists in the theme compiler and allows an attacker to craft a malformed theme that triggers uncontrolled recursion. When the web client processes such a theme the recursion can cause the browser to consume excessive resources, leading to significant slowdown or a crash, which results in a denial of service for users interacting with the client.

Affected Systems

The issue affects misskey-dev’s Misskey platform. All versions starting at 8.63.0 and up to, but not including, 2026.5.4 are vulnerable. The fix is included in release 2026.5.4 and later releases.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not widely exploited yet. An attacker can exploit it by providing a malicious theme to the web client—either by uploading it as an authorized user or by tricking a regular user into loading a theme file—so the risk is contingent on the attacker’s ability to influence theme selection.

Generated by OpenCVE AI on August 4, 2026 at 09:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to version 2026.5.4 or later.
  • Restrict theme uploads to trusted users.
  • Monitor system performance for anomalies.

Generated by OpenCVE AI on August 4, 2026 at 09:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Misskey
Misskey misskey
Vendors & Products Misskey
Misskey misskey

Mon, 03 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Misskey is an open source, federated social media platform. IVersions 8.63.0 and later, but prior to 2026.5.4, contain a vulnerability that can cause the Misskey web client to slow down or crash when it applies a malformed theme. This issue has been fixed in version 2026.5.4.
Title Misskey: Denial of Service via Uncontrolled Recursion in Theme Compilation
Weaknesses CWE-674
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-05T14:27:42.341Z

Reserved: 2026-05-15T23:26:58.309Z

Link: CVE-2026-46714

cve-icon Vulnrichment

Updated: 2026-08-05T14:27:36.688Z

cve-icon NVD

Status : Received

Published: 2026-08-03T22:16:49.167

Modified: 2026-08-05T15:16:49.463

Link: CVE-2026-46714

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T09:45:06Z

Weaknesses