Impact
Misskey is an open source federated social media platform that suffered a timing attack during JSON‑LD signature validation and compaction. The application does not reuse the JSON‑LD parsing context between the signature verification step and the later processing step, creating a time‑of‑check to time‑of‑use vulnerability. An attacker who can supply crafted JSON‑LD input can force Misskey to accept fraudulent data as valid, thereby eroding the integrity of user actions and content.
Affected Systems
The affected vendor is misskey‑dev, and the product is the Misskey platform. All releases from version 12.37.0 up to but excluding 2026.5.4 are vulnerable. The issue was addressed and fixed in version 2026.5.4.
Risk and Exploitability
The CVSS score of 8.9 signals high severity, yet the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply malicious JSON‑LD content to the federated network; timing differences in the library allow the attacker to influence the outcome of the signature check. Although no public exploit is currently documented, the flaw’s nature and lack of common‑source context sharing render it actionable in a federated environment.
OpenCVE Enrichment