Known vulnerabilities in Misskey 2026.7.0

Software: Misskey
Version: 2026.7.0
Software CPE: cpe:2.3:a:misskey_development_division:misskey:*:*:*:*:*:*:*:*
Total vulnerabilities: 6
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Misskey version 2026.7.0 Misskey 2026.7.0 is affected by 6 vulnerabilities: 1 high, 3 medium, 2 low Critical High Medium Low

Vulnerabilities (6)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU150218 - Improper Control of Resource Identifiers ('Resource Injection')
CWE-99 Medium
No
No
2026.9.0 16.09.2026 SB2026091653
#VU150215 - Heap-based Buffer Overflow
CWE-122 High
No
No
2026.9.0 16.09.2026 SB2026091653
#VU150210 - Improper Link Resolution Before File Access ('Link Following')
CWE-59 Low
No
No
2026.9.0 16.09.2026 SB2026091653
#VU150197 - Missing Authorization
CWE-862 Medium
No
No
2026.9.0 16.09.2026 SB2026091653
#VU150180 - Exposure of Sensitive Information Through Metadata
CWE-1230 Medium
No
No
2026.9.0 16.09.2026 SB2026091653
#VU150175 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-22 Low
No
No
2026.9.0 16.09.2026 SB2026091653