PT-2026-67531 · Misskey · Misskey

CVE-2026-46713

·

Published

2026-08-03

·

Updated

2026-08-04

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Misskey versions 12.37.0 through 2026.5.3
Description A flaw exists in the JSON-LD signature validation and compaction process. This allows spoofed activities to be accepted as valid. JSON-LD is a method of encoding Linked Data using JSON.
Recommendations Update to version 2026.5.4.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46713
GHSA-W8X2-GPQ6-JXVF

Affected Products

Misskey