PT-2026-67533 · Misskey · Misskey

CVE-2026-47746

·

Published

2026-08-03

·

Updated

2026-08-03

CVSS v4.0

8.9

High

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Misskey versions 12.37.0 through 2026.5.3
Description Misskey is an open source, federated social media platform. The software is susceptible to timing attacks during the compaction process and JSON-LD signature validation. A time-of-check to time-of-use (TOCTOU) flaw occurs because the JSON-LD parsing context is not shared between signature verification and subsequent processing. This allows an attacker to bypass integrity checks and have fraudulent activities accepted as valid.
Recommendations Update to version 2026.5.4.

Exploit

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47746
GHSA-38JX-423M-G387

Affected Products

Misskey