Input validation error in Misskey - CVE-2025-46340

 

Input validation error in Misskey - CVE-2025-46340

Published: April 28, 2026


Vulnerability identifier: #VU128338
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-46340
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information and modify the user interface.

The vulnerability exists due to improper input validation in MkUrlPreview when rendering URL preview metadata into a background-image style. A remote attacker can supply a specially crafted URL preview image value to disclose sensitive information and modify the user interface.

An attacker can inject arbitrary CSS into the preview element, which can be used to display deceptive content such as a fake error message intended to trick users into revealing credentials.


Affected software

Misskey

How to mitigate CVE-2025-46340

Install security update from vendor's website.

Misskey - update to 2025.4.1

External References

Related Security Bulletins