CVE-2021-39195
HIGHMisskey < 12.90.0 - Server-Side Request Forgery via Upload from URL
Title source: llmDescription
Misskey is an open source, decentralized microblogging platform. In affected versions a Server-Side Request Forgery vulnerability exists in "Upload from URL" and remote attachment handling. This could result in the disclosure of non-public information within the internal network. This has been fixed in 12.90.0. However, if you are using a proxy, you will need to take additional measures. As a workaround this exploit may be avoided by appropriately restricting access to private networks from the host where the application is running.
References (3)
Core 3
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://github.com/misskey-dev/misskey/security/advisories/GHSA-mqv7-gxh4-r5vf
Patch, Third Party Advisory x_refsource_misc
https://github.com/misskey-dev/misskey/commit/e1a8b158e04ad567d92d8daf3cc0898ee18f1a2e
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/misskey-dev/misskey/blob/develop/CHANGELOG.md#12900-20210904
Scores
CVSS v3
7.7
EPSS
0.0103
EPSS Percentile
59.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Details
CWE
CWE-918
Status
published
Products (1)
misskey/misskey
< 12.90.0
Published
Sep 07, 2021
Tracked Since
Feb 18, 2026