PT-2026-67533 · Misskey · Misskey
CVE-2026-47746
·
Published
2026-08-03
·
Updated
2026-08-03
CVSS v4.0
8.9
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Misskey versions 12.37.0 through 2026.5.3
Description
Misskey is an open source, federated social media platform. The software is susceptible to timing attacks during the compaction process and JSON-LD signature validation. A time-of-check to time-of-use (TOCTOU) flaw occurs because the JSON-LD parsing context is not shared between signature verification and subsequent processing. This allows an attacker to bypass integrity checks and have fraudulent activities accepted as valid.
Recommendations
Update to version 2026.5.4.
Exploit
Fix
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misskey