Misskey ActivityPub Object Forgery Vulnerability

Vulnerability

A vulnerability in Misskey's ActivityPub implementation allows for the forgery of objects by improperly validating the relationship between the 'id' and 'url' fields. This issue is present in Misskey versions through 2025.2.0. An attacker can exploit this vulnerability to claim authority in the 'url' field, even when the ActivityPub object type requires authority in the 'id' field. This flaw arises from an incomplete patch for a previous vulnerability, CVE-2024-52591.

Impact

Exploitation of this vulnerability could lead to unauthorized manipulation of ActivityPub objects, allowing attackers to falsely assert authority over certain content.

Remediation

Users can upgrade to Misskey version 2025.2.1 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
0.6
exploitability
8.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.