Input validation error in Misskey - CVE-2025-46559
Published: April 28, 2026
Misskey
Detailed vulnerability description
The vulnerability allows a remote user to access unintended endpoints and modify data.
The vulnerability exists due to improper input validation in the Mk:api function when processing user-supplied endpoint paths. A remote user can supply a path prefixed with ../ to access unintended endpoints and modify data.
User interaction is required to execute malicious AiScript code.