Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025.12.0, an actor who does not have permission to view favorites or clips can can export the posts and view the contents. Version 2025.12.0 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Mon, 15 Dec 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025.12.0, an actor who does not have permission to view favorites or clips can can export the posts and view the contents. Version 2025.12.0 fixes the issue. | |
| Title | misskey.js's export data contains private post data | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-15T23:09:57.681Z
Reserved: 2025-11-28T23:33:56.364Z
Link: CVE-2025-66402
No data.
Status : Received
Published: 2025-12-16T00:16:02.207
Modified: 2025-12-16T00:16:02.207
Link: CVE-2025-66402
No data.
OpenCVE Enrichment
No data.