Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 05 Aug 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Misskey
Misskey misskey |
|
| Vendors & Products |
Misskey
Misskey misskey |
Tue, 04 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD signature validation and compaction process that allows spoofed activities to be accepted as valid. This issue has been fixed in version 2026.5.4. | |
| Title | Misskey: JSON-LD signature validation + compaction may lead to improper activity handling | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-04T15:44:53.013Z
Reserved: 2026-05-15T23:26:58.309Z
Link: CVE-2026-46713
Updated: 2026-08-04T15:44:31.112Z
Status : Received
Published: 2026-08-03T22:16:49.017
Modified: 2026-08-04T17:16:54.770
Link: CVE-2026-46713
No data.
OpenCVE Enrichment
Updated: 2026-08-05T09:45:06Z