CVE-2026-46713
Received Received - Intake

JSON-LD Signature Validation Bypass in Misskey

Vulnerability report for CVE-2026-46713, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: GitHub, Inc.

Description

Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD signature validation and compaction process that allows spoofed activities to be accepted as valid. This issue has been fixed in version 2026.5.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
misskey misskey From 12.37.0 (inc) to 2026.5.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Misskey versions 12.37.0 to 2026.5.3 have a flaw in JSON-LD signature validation and compaction. This allows attackers to spoof activities, making them appear as valid when they are not.

Impact Analysis

An attacker could forge activities on your Misskey instance, potentially spreading false information or impersonating users. This could disrupt trust and communication within the federated network.

Mitigation Strategies

Upgrade Misskey to version 2026.5.4 or later to address the vulnerability in JSON-LD signature validation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-46713. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart