SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-46713

CRITICAL · CVSS 9.2 EPSS 0.17% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

Misskey, an open-source federated social media platform, is vulnerable in versions 12.37.0 through 2026.5.3 due to flaws in its JSON-LD signature validation and compaction process, which can lead to the acceptance of spoofed activities as legitimate. This vulnerability poses a risk to the integrity of user interactions on the platform. Organizations using affected versions should prioritize upgrading to version 2026.5.4 to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-46713
Severity
CRITICAL
CVSS
9.2
EPSS
0.17%

Original NVD Description

Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD signature validation and compaction process that allows spoofed activities to be accepted as valid. This issue has been fixed in version 2026.5.4.