Misskey is an open source, federated social media platform. Starting in version 12.31.0 and prior to version 2025.4.1, missing validation in `Mk:api` allows malicious AiScript code to access additional endpoints that it isn't designed to have access to. The missing validation allows malicious AiScript code to prefix a URL with `../` to step out of the `/api` directory, thereby being able to make requests to other endpoints, such as `/files`, `/url`, and `/proxy`. Version 2025.4.1 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Mon, 05 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 05 May 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Misskey is an open source, federated social media platform. Starting in version 12.31.0 and prior to version 2025.4.1, missing validation in `Mk:api` allows malicious AiScript code to access additional endpoints that it isn't designed to have access to. The missing validation allows malicious AiScript code to prefix a URL with `../` to step out of the `/api` directory, thereby being able to make requests to other endpoints, such as `/files`, `/url`, and `/proxy`. Version 2025.4.1 fixes the issue. | |
Title | Misskey Directory Traversal Vulnerability in AiScript via `Mk:api` | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-05-05T18:38:36.144Z
Updated: 2025-05-05T18:44:52.723Z
Reserved: 2025-04-24T21:10:48.173Z
Link: CVE-2025-46559

Updated: 2025-05-05T18:44:37.225Z

Status : Awaiting Analysis
Published: 2025-05-05T19:15:56.910
Modified: 2025-05-05T20:54:19.760
Link: CVE-2025-46559

No data.