Input validation error in Misskey - CVE-2024-52590
Published: December 18, 2024 / Updated: April 28, 2026
Misskey
Detailed vulnerability description
The vulnerability allows a remote attacker to impersonate users on another instance.
The vulnerability exists due to improper input validation in ApRequestService.signedGet when validating signed profile requests. A remote attacker can create a spoofed user profile to impersonate users on another instance.
The spoofed profile may appear to originate from a different instance than the one where it actually exists, and the attacker has full control over that spoofed account.