Impact
Misskey’s Time‑based One‑Time Password authentication allows a single‑use code to be replayed within its valid time window because the system does not record used tokens. An attacker who obtains both a victim’s login credentials and a concurrent TOTP code can reuse that code to authenticate as the victim and perform any action permitted by those credentials, potentially a failure to enforce one‑time usage of TOTP tokens and is classified as CWE‑294.
Affected Systems
The vulnerability affects Misskey instances running any version prior to 2026.6.0. The affected vendor is misskey-dev, product Misskey.
Risk and Exploitability
The CVSS v3 score of 7.4 denotes high severity, while an EPSS score of < 1 % indicates a very low but probability vulnerability is not listed in the CISA KEV catalog, but that does not mitigate its potential impact. Based on the description, it is inferred that the attack vector requires an attacker to first compromise a user by credential theft or phishing—and simultaneously With both pieces of information, the attacker can replay the same code within the same time step authorized action, potentially enabling account takeover.
OpenCVE Enrichment