We found results for “”
CVE-2025-66402
Good to know:
Date: December 15, 2025
Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025.12.0, an actor who does not have permission to view favorites or clips can can export the posts and view the contents. Version 2025.12.0 fixes the issue.
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
Missing Authorization
CWE-862Top Fix
Upgrade Version
Upgrade to version misskey-js - 2025.12.0;https://github.com/misskey-dev/misskey.git - 2025.12.0
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | NONE |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


