CVE-2025-25306CRITICAL 9.3EPSS p6.2%
CVE-2025-25306CVE-2025-25306
Description
Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate the relation between the `id` and `url` fields of ActivityPub objects. An attacker can forge an object where they claim authority in the `url` field even if the specific ActivityPub object type require authority in the `id` field. Version 2025.2.1 addresses the issue.
Scoring
| CVSS 3.1 | 9.3 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N |
| EPSS | 0.17% probability of exploitation · percentile 6.2% · 2026-06-18T12:00:27Z |
| Published | 2025-03-10 |
| Last modified | 2025-11-26 |
Underlying weaknesses· 3
References
3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Comparison Using Wrong Factorscwe-1025 | 0% | live |
| Weakness | Origin Validation Errorcwe-346 | 0% | live |
| Weakness | Unintended Proxy or Intermediary ('Confused Deputy')cwe-441 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.