# CVE-2025-25306

## Summary

- **CVE ID:** CVE-2025-25306
- **Severity:** CRITICAL
- **CVSS Score:** 9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N)
- **CWE:** CWE-346, CWE-441, CWE-1025
- **Published:** Mar 10, 2025
- **Last Modified:** Mar 12, 2026

## Description

Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate the relation between the `id` and `url` fields of ActivityPub objects. An attacker can forge an object where they claim authority in the `url` field even if the specific ActivityPub object type require authority in the `id` field. Version 2025.2.1 addresses the issue.

## Affected Products

- misskey-dev — misskey (< 2025.2.1)

## References

- [CNA](https://github.com/misskey-dev/misskey/security/advisories/GHSA-6w2c-vf6f-xf26)
- [CNA](https://github.com/misskey-dev/misskey/releases/tag/2025.2.1)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.17%
- **EPSS Percentile:** 6.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._