CVE-2025-66402

Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025.12.0, an actor who does not have permission to view favorites or clips can can export the posts and view the contents. Version 2025.12.0 fixes the issue.
CVSS

No CVSS.

Configurations

No configuration.

History

16 Dec 2025, 16:16

Type Values Removed Values Added
References () https://github.com/misskey-dev/misskey/security/advisories/GHSA-496g-mmpw-j9x3 - () https://github.com/misskey-dev/misskey/security/advisories/GHSA-496g-mmpw-j9x3 -

16 Dec 2025, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-16 00:16

Updated : 2025-12-16 16:16


NVD link : CVE-2025-66402

Mitre link : CVE-2025-66402

CVE.ORG link : CVE-2025-66402


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization