Misskey is a small-footprint open-source social-networking platform whose vulnerability profile, despite a narrow product range, has attracted attention within the broader fediverse ecosystem. The vendor's disclosures skew toward serious outcomes, with a meaningful share reaching critical severity, and concentrate in its core Misskey application and related tooling such as Summaly. Vulnerabilities recur through web-application weakness classes including improper input validation, cross-site scripting, authorization bypass, and cryptographic verification flaws that are characteristic of federated social platforms handling user-generated content and inter-server trust relationships. Defenders deploying or federating with Misskey instances should treat security advisories as high-priority despite the narrow product scope, given the interconnected nature of fediverse deployments. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Misskey over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-52139CRITICAL Misskey is an open source, decentralized social media platform. Third-party applications may be able to access some endpoints or Websocket APIs that are incorrectly specified as [k | Dec 29, 2023 | 9.6 | 29 | NO | NO |
CVE-2023-24812CRITICAL Misskey is an open source, decentralized social media platform. In versions prior to 13.3.3 SQL injection is possible due to insufficient parameter validation in the note search AP | Feb 22, 2023 | 9.8 | 29 | NO | NO |
CVE-2025-25306CRITICAL Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate the relation between the `id` and `url` fields of ActivityPub | Mar 10, 2025 | 9.3 | 26 | NO | NO |
CVE-2024-52591CRITICAL Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService.signedGet` and `HttpRequestService.getActivityJson` allows | Dec 18, 2024 | 9.3 | 26 | NO | NO |
CVE-2024-25636HIGH Misskey is an open source, decentralized social media platform with ActivityPub support. Prior to version 2024.2.0, when fetching remote Activity Streams objects, Misskey doesn't c | Feb 19, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-49079HIGH Misskey is an open source, decentralized social media platform. Misskey's missing signature validation allows arbitrary users to impersonate any remote user. This issue has been pa | Nov 29, 2023 | 7.5 | 24 | NO | NO |
CVE-2024-32983HIGH Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSON structures of incoming signed ActivityPub activity objects | Jun 3, 2024 | 7.5 | 23 | NO | NO |
CVE-2026-28432HIGH Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerability that allows bypassing HTTP signature verification. Althoug | Mar 10, 2026 | 7.5 | 22 | NO | NO |
CVE-2026-28431HIGH Misskey is an open source, federated social media platform. All Misskey servers running versions 8.45.0 and later, but prior to 2026.3.1, contain a vulnerability that allows bad ac | Mar 10, 2026 | 7.5 | 22 | NO | NO |
CVE-2025-66482MEDIUM Misskey is an open source, federated social media platform. Attackers who use an untrusted reverse proxy or not using a reverse proxy at all can bypass IP rate limiting by adding a | Dec 16, 2025 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Misskey.
Media articles that mention a CVE ID that affects a product developed by Misskey — matched by CVE ID, not by vendor name.