Cross-site request forgery in Misskey - CVE-2025-24897
Published: February 11, 2025 / Updated: April 28, 2026
Misskey
Detailed vulnerability description
The vulnerability allows a remote attacker to perform cross-site request forgery attacks against bull-board APIs.
The vulnerability exists due to cross-site request forgery in bull-board APIs when handling authenticated requests with insecure authentication cookie attributes. A remote attacker can cause the victim's browser to send a crafted request to perform cross-site request forgery attacks against bull-board APIs.
User interaction is required for exploitation.