CVE Vulnerabilities

CVE-2025-25306

Origin Validation Error

Published: Mar 10, 2025 | Modified: Nov 26, 2025
CVSS 3.x
9.3
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate the relation between the id and url fields of ActivityPub objects. An attacker can forge an object where they claim authority in the url field even if the specific ActivityPub object type require authority in the id field. Version 2025.2.1 addresses the issue.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

Name Vendor Start Version End Version
Misskey Misskey * 2025.2.1 (excluding)

References