CVE-2024-25636 is a high-severity vulnerability affecting Misskey, an open-source decentralized social media platform, prior to version 2024.2.0. The flaw, categorized as CWE-434 (Unrestricted Upload of File with Dangerous Type), allows an attacker to impersonate and take over accounts on vulnerable remote servers due to improper validation of Activity Streams object content types. The vulnerability carries a CVSS score of 8.8 (HIGH), indicating a network-based attack with low attack complexity and no user interaction required, leading to high impacts on confidentiality, integrity, and availability. Exploitation requires specific conditions on the remote server, including arbitrary user uploads and specific content serving behaviors. Currently, there is no evidence of active exploitation, nor are there publicly available exploit codes in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for the majority of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2024.2.0CPE matchmatch criteria | cpe:2.3:a:misskey:misskey:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.