CVE-2025-24897
Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, due to a lack of CSRF protection and the lack of proper security attributes in the authentication cookies of Bull's dashboard, some of the APIs of bull-board may be subject to CSRF attacks. There is a risk of this vulnerability being used for attacks with relatively large impact on availability and integrity, such as the ability to add arbitrary jobs. This vulnerability was fixed in 2025.2.0-alpha.0. As a workaround, block all access to the `/queue` directory with a web application firewall (WAF).
Scoring
- Severity
- HIGH
- CVSS base score
- 8.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L
- EPSS probability
- 0.14%
- CWE
- CWE-352, CWE-614, CWE-1275
- Published
- 2025-02-11
- Last modified
- 2026-03-12
Affected products
- misskey-dev misskey
Weakness type
Related vulnerabilities
- CVE-2026-49992 — Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure Changes
- CVE-2026-50025 — Mousehole: Unauthenticated HTTP/WebSocket boundary exposes and mutates MAM cookie state
- CVE-2026-81907 — Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) vin Express delete_entries allowing mass deletion of all entity records
- CVE-2026-68526 — Concrete CMS before 9.5.3 is vulnerable to CSRF in the Calendar event duplicate dialog controller
- CVE-2026-81912 — Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature
- CVE-2026-62139 — WordPress Site Kit by Google plugin <= 1.186.0 - Cross Site Request Forgery (CSRF) vulnerability
- CVE-2026-62133 — WordPress RTMKit plugin <= 2.1.5 - Cross Site Request Forgery (CSRF) vulnerability
- CVE-2026-89245 — WWBN AVideo Cross-Site Request Forgery via playlistRemove.php