Misskey
cpe:2.3:a:misskey:misskey:*:*:*:*:*:*:*
- >= 8.45.0, < 2026.3.1
A vulnerability in Misskey, an open-source federated social media platform, allows unauthorized access to data on servers running versions 8.45.0 and later, but prior to 2026.3.1. This issue arises from inadequate permission checks and input validation, potentially leading to a significant data breach. The vulnerability exists regardless of whether federation is enabled.
Exploitation of this vulnerability could result in unauthorized data access, leading to a substantial data breach.
Users are advised to update to Misskey version 2026.3.1 or later. There is no known workaround for this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.