CVE 7.1 HIGH

misskey.js’s export data contains private post data_CVE-2025-66402

7.1 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025.12.0, an actor who does not have permission to view favorites or clips can can export the posts and view the contents. Version 2025.12.0 fixes the issue.

Basic Information

ID CVE-2025-66402
Source GitHub_M
Published Dec 15, 2025 at 23:09

Affected Product

Vendor misskey-dev
Product misskey
Version >= 13.0.0-beta.16, < 2025.12.0
Affected Versions misskey-dev misskey >= 13.0.0-beta.16, < 2025.12.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.