misskey-js
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting misskey-jspage 1 of 1
- CVE-2025-66402MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2025.12.02025-12-16
Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025.12.0, an actor who does not have permission to view favorites or clips can can export the posts and view the contents.…
- CVE-2025-66482MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2025.12.0-alpha.22025-12-16
Misskey is an open source, federated social media platform. Attackers who use an untrusted reverse proxy or not using a reverse proxy at all can bypass IP rate limiting by adding a forged X-Forwarded-For header. Starting with version 2025.…
Check whether misskey-js is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for misskey-js CVEs against the assets you own.
Start Free Scan →