Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-52591

26
FAUCET Score

CVE-2024-52591 is a critical vulnerability affecting Misskey, an open-source federated social media platform. It stems from missing validation in specific services, allowing attackers to create fake user profiles and forged notes that appear to originate from different instances or users. This enables impersonation and full control over spoofed accounts. The vulnerability has a CVSS score of 9.3 (CRITICAL), indicating a network-exploitable flaw with low attack complexity and high impact on integrity, potentially leading to data compromise. There are no known workarounds. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE. Users are advised to upgrade to version 2024.11.0-alpha.3 or later to mitigate the risk.

Impacted Technologies

VendorProductVersion(s)CPE
< 2024.11.0CPE matchmatch criteria
cpe:2.3:a:misskey:misskey:*:*:*:*:*:*:*:*
2024.11.0CPE matchmatch criteria
cpe:2.3:a:misskey:misskey:2024.11.0:alpha0:*:*:*:*:*:*
2024.11.0CPE matchmatch criteria
cpe:2.3:a:misskey:misskey:2024.11.0:alpha1:*:*:*:*:*:*
2024.11.0CPE matchmatch criteria
cpe:2.3:a:misskey:misskey:2024.11.0:alpha2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.8HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
LOW
SS Integrity
NONE
SS Availability
LOW
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.32%
Probability of exploitation in next 30 days
EPSS Percentile
24.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0032 is in the 4th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

misskeypatch availablevia llm_extracted
View patch
freebsdvendor investigatingvia llm_extracted
m2teamvendor investigatingvia llm_extracted
masacmsvendor investigatingvia llm_extracted
paloalto_prismavendor investigatingvia llm_extracted
ranchervendor investigatingvia llm_extracted

Vendor Advisories (6)

freebsdllm-freebsd-16f9a93d7cbe7a8cCRITICAL

Incomplete Patch on CVE-2024-52591 leading to Forgery of Federated Notes

Mar 8, 2025
m2teamllm-m2team-f81fcf696bc74b8eCRITICAL

Incomplete Patch on CVE-2024-52591 leading to Forgery of Federated Notes

Mar 8, 2025
misskeyllm-misskey-4728c6bfe1cbc40cCRITICAL

Incomplete Patch on CVE-2024-52591 leading to Forgery of Federated Notes

Mar 8, 2025
masacmsllm-masacms-1aa995b7dd2587bbCRITICAL

Incomplete Patch on CVE-2024-52591 leading to Forgery of Federated Notes

Mar 8, 2025
paloalto_prismallm-paloalto_prisma-67d5cc80e935202eCRITICAL

Incomplete Patch on CVE-2024-52591 leading to Forgery of Federated Notes

Mar 8, 2025
rancherllm-rancher-ed3e4c23d8c0a3b0CRITICAL

Incomplete Patch on CVE-2024-52591 leading to Forgery of Federated Notes

Mar 8, 2025

References

github.com / misskey-dev/misskey/security/advisories/GHSA-m2gq-69fp-6hv4
Third Party Advisory