CVE-2025-66402

MEDIUM

Misskey <2025.12.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025.12.0, an actor who does not have permission to view favorites or clips can can export the posts and view the contents. Version 2025.12.0 fixes the issue.

Scores

CVSS v3 6.5
EPSS 0.0005
EPSS Percentile 14.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (3)
misskey/misskey 13.0.0 (36 CPE variants)
misskey/misskey 13.1.0 - 2025.12.0
npm/misskey-js 13.0.0-beta.16 - 2025.12.0npm
Published Dec 16, 2025
Tracked Since Feb 18, 2026