Vulnerability Details CVE-2024-52593
Misskey is an open source, federated social media platform.In affected versions missing validation in `NoteCreateService.insertNote`, `ApPersonService.createPerson`, and `ApPersonService.updatePerson` allows an attacker to control the target of any "origin" links (such as the "view on remote instance" banner). Any HTTPS URL can be set, even if it belongs to a different domain than the note / user. Vulnerable Misskey instances will use the unverified URL for several clickable links, allowing an attacker to conduct phishing or other attacks against remote users. This issue has been addressed in version 2024.11.0-alpha.3. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 29.6%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2024-52593
-
cpe:2.3:a:misskey:misskey:12.100.0
-
cpe:2.3:a:misskey:misskey:12.100.1
-
cpe:2.3:a:misskey:misskey:12.100.2
-
cpe:2.3:a:misskey:misskey:12.101.0
-
cpe:2.3:a:misskey:misskey:12.101.1
-
cpe:2.3:a:misskey:misskey:12.102.0
-
cpe:2.3:a:misskey:misskey:12.102.1
-
cpe:2.3:a:misskey:misskey:12.103.0
-
cpe:2.3:a:misskey:misskey:12.103.1
-
cpe:2.3:a:misskey:misskey:12.104.0
-
cpe:2.3:a:misskey:misskey:12.105.0
-
cpe:2.3:a:misskey:misskey:12.106.0
-
cpe:2.3:a:misskey:misskey:12.106.1
-
cpe:2.3:a:misskey:misskey:12.106.2
-
cpe:2.3:a:misskey:misskey:12.106.3
-
cpe:2.3:a:misskey:misskey:12.107.0
-
cpe:2.3:a:misskey:misskey:12.108.0
-
cpe:2.3:a:misskey:misskey:12.108.1
-
cpe:2.3:a:misskey:misskey:12.109.0
-
cpe:2.3:a:misskey:misskey:12.109.1
-
cpe:2.3:a:misskey:misskey:12.109.2
-
cpe:2.3:a:misskey:misskey:12.110.0
-
cpe:2.3:a:misskey:misskey:12.110.1
-
cpe:2.3:a:misskey:misskey:12.111.0
-
cpe:2.3:a:misskey:misskey:12.111.1
-
cpe:2.3:a:misskey:misskey:12.112.0
-
cpe:2.3:a:misskey:misskey:12.112.1
-
cpe:2.3:a:misskey:misskey:12.112.2
-
cpe:2.3:a:misskey:misskey:12.112.3
-
cpe:2.3:a:misskey:misskey:12.113.0
-
cpe:2.3:a:misskey:misskey:12.114.0
-
cpe:2.3:a:misskey:misskey:12.115.0
-
cpe:2.3:a:misskey:misskey:12.116.0
-
cpe:2.3:a:misskey:misskey:12.116.1
-
cpe:2.3:a:misskey:misskey:12.117.0
-
cpe:2.3:a:misskey:misskey:12.117.1
-
cpe:2.3:a:misskey:misskey:12.118.0
-
cpe:2.3:a:misskey:misskey:12.118.1
-
cpe:2.3:a:misskey:misskey:12.119.0
-
cpe:2.3:a:misskey:misskey:12.119.1
-
cpe:2.3:a:misskey:misskey:12.119.2
-
cpe:2.3:a:misskey:misskey:12.29.0
-
cpe:2.3:a:misskey:misskey:12.30.0
-
cpe:2.3:a:misskey:misskey:12.31.0
-
cpe:2.3:a:misskey:misskey:12.32.0
-
cpe:2.3:a:misskey:misskey:12.33.0
-
cpe:2.3:a:misskey:misskey:12.34.0
-
cpe:2.3:a:misskey:misskey:12.35.0
-
cpe:2.3:a:misskey:misskey:12.35.1
-
cpe:2.3:a:misskey:misskey:12.35.2
-
cpe:2.3:a:misskey:misskey:12.36.0
-
cpe:2.3:a:misskey:misskey:12.36.1
-
cpe:2.3:a:misskey:misskey:12.37.0
-
cpe:2.3:a:misskey:misskey:12.38.0
-
cpe:2.3:a:misskey:misskey:12.38.1
-
cpe:2.3:a:misskey:misskey:12.39.0
-
cpe:2.3:a:misskey:misskey:12.39.1
-
cpe:2.3:a:misskey:misskey:12.40.0
-
cpe:2.3:a:misskey:misskey:12.41.0
-
cpe:2.3:a:misskey:misskey:12.41.1
-
cpe:2.3:a:misskey:misskey:12.41.2
-
cpe:2.3:a:misskey:misskey:12.41.3
-
cpe:2.3:a:misskey:misskey:12.42.0
-
cpe:2.3:a:misskey:misskey:12.43.0
-
cpe:2.3:a:misskey:misskey:12.44.0
-
cpe:2.3:a:misskey:misskey:12.44.1
-
cpe:2.3:a:misskey:misskey:12.45.0
-
cpe:2.3:a:misskey:misskey:12.45.1
-
cpe:2.3:a:misskey:misskey:12.46.0
-
cpe:2.3:a:misskey:misskey:12.47.0
-
cpe:2.3:a:misskey:misskey:12.47.1
-
cpe:2.3:a:misskey:misskey:12.48.0
-
cpe:2.3:a:misskey:misskey:12.48.1
-
cpe:2.3:a:misskey:misskey:12.48.2
-
cpe:2.3:a:misskey:misskey:12.48.3
-
cpe:2.3:a:misskey:misskey:12.49.0
-
cpe:2.3:a:misskey:misskey:12.49.1
-
cpe:2.3:a:misskey:misskey:12.50.0
-
cpe:2.3:a:misskey:misskey:12.51.0
-
cpe:2.3:a:misskey:misskey:12.52.0
-
cpe:2.3:a:misskey:misskey:12.53.0
-
cpe:2.3:a:misskey:misskey:12.54.0
-
cpe:2.3:a:misskey:misskey:12.55.0
-
cpe:2.3:a:misskey:misskey:12.56.0
-
cpe:2.3:a:misskey:misskey:12.57.0
-
cpe:2.3:a:misskey:misskey:12.57.1
-
cpe:2.3:a:misskey:misskey:12.57.4
-
cpe:2.3:a:misskey:misskey:12.58.0
-
cpe:2.3:a:misskey:misskey:12.59.0
-
cpe:2.3:a:misskey:misskey:12.60.0
-
cpe:2.3:a:misskey:misskey:12.60.1
-
cpe:2.3:a:misskey:misskey:12.61.0
-
cpe:2.3:a:misskey:misskey:12.61.1
-
cpe:2.3:a:misskey:misskey:12.62.0
-
cpe:2.3:a:misskey:misskey:12.62.1
-
cpe:2.3:a:misskey:misskey:12.62.2
-
cpe:2.3:a:misskey:misskey:12.63.0
-
cpe:2.3:a:misskey:misskey:12.64.0
-
cpe:2.3:a:misskey:misskey:12.64.1
-
cpe:2.3:a:misskey:misskey:12.64.2
-
cpe:2.3:a:misskey:misskey:12.65.0
-
cpe:2.3:a:misskey:misskey:12.65.1
-
cpe:2.3:a:misskey:misskey:12.65.2
-
cpe:2.3:a:misskey:misskey:12.65.3
-
cpe:2.3:a:misskey:misskey:12.65.4
-
cpe:2.3:a:misskey:misskey:12.65.5
-
cpe:2.3:a:misskey:misskey:12.65.6
-
cpe:2.3:a:misskey:misskey:12.65.7
-
cpe:2.3:a:misskey:misskey:12.66.0
-
cpe:2.3:a:misskey:misskey:12.67.0
-
cpe:2.3:a:misskey:misskey:12.67.1
-
cpe:2.3:a:misskey:misskey:12.68.0
-
cpe:2.3:a:misskey:misskey:12.69.0
-
cpe:2.3:a:misskey:misskey:12.70.0
-
cpe:2.3:a:misskey:misskey:12.71.0
-
cpe:2.3:a:misskey:misskey:12.72.0
-
cpe:2.3:a:misskey:misskey:12.73.0
-
cpe:2.3:a:misskey:misskey:12.74.0
-
cpe:2.3:a:misskey:misskey:12.74.1
-
cpe:2.3:a:misskey:misskey:12.75.0
-
cpe:2.3:a:misskey:misskey:12.75.1
-
cpe:2.3:a:misskey:misskey:12.76.0
-
cpe:2.3:a:misskey:misskey:12.76.1
-
cpe:2.3:a:misskey:misskey:12.77.0
-
cpe:2.3:a:misskey:misskey:12.77.1
-
cpe:2.3:a:misskey:misskey:12.78.0
-
cpe:2.3:a:misskey:misskey:12.79.0
-
cpe:2.3:a:misskey:misskey:12.79.1
-
cpe:2.3:a:misskey:misskey:12.79.2
-
cpe:2.3:a:misskey:misskey:12.79.3
-
cpe:2.3:a:misskey:misskey:12.80.0
-
cpe:2.3:a:misskey:misskey:12.80.1
-
cpe:2.3:a:misskey:misskey:12.80.2
-
cpe:2.3:a:misskey:misskey:12.80.3
-
cpe:2.3:a:misskey:misskey:12.81.0
-
cpe:2.3:a:misskey:misskey:12.81.1
-
cpe:2.3:a:misskey:misskey:12.81.2
-
cpe:2.3:a:misskey:misskey:12.82.0
-
cpe:2.3:a:misskey:misskey:12.83.0
-
cpe:2.3:a:misskey:misskey:12.84.0
-
cpe:2.3:a:misskey:misskey:12.84.1
-
cpe:2.3:a:misskey:misskey:12.84.2
-
cpe:2.3:a:misskey:misskey:12.84.3
-
cpe:2.3:a:misskey:misskey:12.85.0
-
cpe:2.3:a:misskey:misskey:12.85.1
-
cpe:2.3:a:misskey:misskey:12.86.0
-
cpe:2.3:a:misskey:misskey:12.87.0
-
cpe:2.3:a:misskey:misskey:12.88.0
-
cpe:2.3:a:misskey:misskey:12.89.0
-
cpe:2.3:a:misskey:misskey:12.89.1
-
cpe:2.3:a:misskey:misskey:12.89.2
-
cpe:2.3:a:misskey:misskey:12.90.0
-
cpe:2.3:a:misskey:misskey:12.90.1
-
cpe:2.3:a:misskey:misskey:12.92.0
-
cpe:2.3:a:misskey:misskey:12.93.0
-
cpe:2.3:a:misskey:misskey:12.93.1
-
cpe:2.3:a:misskey:misskey:12.93.2
-
cpe:2.3:a:misskey:misskey:12.94.0
-
cpe:2.3:a:misskey:misskey:12.94.1
-
cpe:2.3:a:misskey:misskey:12.95.0
-
cpe:2.3:a:misskey:misskey:12.96.0
-
cpe:2.3:a:misskey:misskey:12.96.1
-
cpe:2.3:a:misskey:misskey:12.97.0
-
cpe:2.3:a:misskey:misskey:12.97.1
-
cpe:2.3:a:misskey:misskey:12.98.0
-
cpe:2.3:a:misskey:misskey:12.99.0
-
cpe:2.3:a:misskey:misskey:12.99.1
-
cpe:2.3:a:misskey:misskey:12.99.2
-
cpe:2.3:a:misskey:misskey:12.99.3
-
cpe:2.3:a:misskey:misskey:13.0.0
-
cpe:2.3:a:misskey:misskey:13.1.0
-
cpe:2.3:a:misskey:misskey:13.1.1
-
cpe:2.3:a:misskey:misskey:13.1.2
-
cpe:2.3:a:misskey:misskey:13.1.3
-
cpe:2.3:a:misskey:misskey:13.1.4
-
cpe:2.3:a:misskey:misskey:13.1.5
-
cpe:2.3:a:misskey:misskey:13.1.6
-
cpe:2.3:a:misskey:misskey:13.1.7
-
cpe:2.3:a:misskey:misskey:13.1.8
-
cpe:2.3:a:misskey:misskey:13.10.0
-
cpe:2.3:a:misskey:misskey:13.10.1
-
cpe:2.3:a:misskey:misskey:13.10.2
-
cpe:2.3:a:misskey:misskey:13.10.3
-
cpe:2.3:a:misskey:misskey:13.11.0
-
cpe:2.3:a:misskey:misskey:13.11.1
-
cpe:2.3:a:misskey:misskey:13.11.2
-
cpe:2.3:a:misskey:misskey:13.11.3
-
cpe:2.3:a:misskey:misskey:13.12.0
-
cpe:2.3:a:misskey:misskey:13.12.1
-
cpe:2.3:a:misskey:misskey:13.12.2
-
cpe:2.3:a:misskey:misskey:13.13.0
-
cpe:2.3:a:misskey:misskey:13.13.1
-
cpe:2.3:a:misskey:misskey:13.13.2
-
cpe:2.3:a:misskey:misskey:13.14.0
-
cpe:2.3:a:misskey:misskey:13.14.1
-
cpe:2.3:a:misskey:misskey:13.14.2
-
cpe:2.3:a:misskey:misskey:13.2.0
-
cpe:2.3:a:misskey:misskey:13.2.1
-
cpe:2.3:a:misskey:misskey:13.2.2
-
cpe:2.3:a:misskey:misskey:13.2.3
-
cpe:2.3:a:misskey:misskey:13.2.4
-
cpe:2.3:a:misskey:misskey:13.2.5
-
cpe:2.3:a:misskey:misskey:13.2.6
-
cpe:2.3:a:misskey:misskey:13.3.0
-
cpe:2.3:a:misskey:misskey:13.3.1
-
cpe:2.3:a:misskey:misskey:13.3.2
-
cpe:2.3:a:misskey:misskey:13.3.3
-
cpe:2.3:a:misskey:misskey:13.3.4
-
cpe:2.3:a:misskey:misskey:13.4.0
-
cpe:2.3:a:misskey:misskey:13.5.0
-
cpe:2.3:a:misskey:misskey:13.5.1
-
cpe:2.3:a:misskey:misskey:13.5.2
-
cpe:2.3:a:misskey:misskey:13.5.3
-
cpe:2.3:a:misskey:misskey:13.5.4
-
cpe:2.3:a:misskey:misskey:13.5.5
-
cpe:2.3:a:misskey:misskey:13.5.6
-
cpe:2.3:a:misskey:misskey:13.6.0
-
cpe:2.3:a:misskey:misskey:13.6.1
-
cpe:2.3:a:misskey:misskey:13.7.0
-
cpe:2.3:a:misskey:misskey:13.7.1
-
cpe:2.3:a:misskey:misskey:13.7.2
-
cpe:2.3:a:misskey:misskey:13.7.3
-
cpe:2.3:a:misskey:misskey:13.7.4
-
cpe:2.3:a:misskey:misskey:13.7.5
-
cpe:2.3:a:misskey:misskey:13.8.0
-
cpe:2.3:a:misskey:misskey:13.8.1
-
cpe:2.3:a:misskey:misskey:13.9.0
-
cpe:2.3:a:misskey:misskey:13.9.1
-
cpe:2.3:a:misskey:misskey:13.9.2
-
cpe:2.3:a:misskey:misskey:2023.10.0
-
cpe:2.3:a:misskey:misskey:2023.10.1
-
cpe:2.3:a:misskey:misskey:2023.10.2
-
cpe:2.3:a:misskey:misskey:2023.11.0
-
cpe:2.3:a:misskey:misskey:2023.11.1
-
cpe:2.3:a:misskey:misskey:2023.12.0
-
cpe:2.3:a:misskey:misskey:2023.12.1
-
cpe:2.3:a:misskey:misskey:2023.12.2
-
cpe:2.3:a:misskey:misskey:2023.9.0
-
cpe:2.3:a:misskey:misskey:2023.9.1
-
cpe:2.3:a:misskey:misskey:2023.9.2
-
cpe:2.3:a:misskey:misskey:2023.9.3
-
cpe:2.3:a:misskey:misskey:2024.10.0
-
cpe:2.3:a:misskey:misskey:2024.10.1
-
cpe:2.3:a:misskey:misskey:2024.10.2
-
cpe:2.3:a:misskey:misskey:2024.11.0
-
cpe:2.3:a:misskey:misskey:2024.2.0
-
cpe:2.3:a:misskey:misskey:2024.3.0
-
cpe:2.3:a:misskey:misskey:2024.3.1
-
cpe:2.3:a:misskey:misskey:2024.5.0
-
cpe:2.3:a:misskey:misskey:2024.7.0
-
cpe:2.3:a:misskey:misskey:2024.8.0
-
cpe:2.3:a:misskey:misskey:2024.9.0