CVE-2023-24810: Cross site scripting (XSS) vulnerability using authentication callback in Misskey
Misskey is an open source, decentralized social media platform. Due to insufficient validation of the redirect URL during miauth authentication in Misskey, arbitrary JavaScript can be executed when a user allows the link. All versions below 13.3.1 (including 12.x) are affected. This has been fixed in version 13.3.1. Users are advised to upgrade. Users unable to upgrade should not allow authentication of untrusted apps.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-24810?
CVE-2023-24810 is a vulnerability in Misskey, an open source decentralized social media platform, that allows arbitrary JavaScript execution due to insufficient validation of the redirect URL during authentication.
How severe is CVE-2023-24810?
CVE-2023-24810 has a severity level of 6.1, which is considered high.
Which versions of Misskey are affected by CVE-2023-24810?
All versions of Misskey below 13.3.1, including 12.x, are affected by CVE-2023-24810.
How can I fix CVE-2023-24810 in Misskey?
To fix CVE-2023-24810 in Misskey, you need to update to version 13.3.1 or higher.
Where can I find more information about CVE-2023-24810?
You can find more information about CVE-2023-24810 in the security advisory on the Misskey GitHub repository: [GitHub Advisory](https://github.com/misskey-dev/misskey/security/advisories/GHSA-cc6r-chgr-8r5m).