CVE-2025-24896: Misskey allows token to remain valid in cookie after signing out

Published Feb 11, 2025
·
Updated

Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, a login token named token is stored in a cookie for authentication purposes in Bull Dashboard, but this remains undeleted even after logout is performed. The primary affected users will be users who have logged into Misskey using a public PC or someone else's device, but it's possible that users who have logged out of Misskey before lending their PC to someone else could also be affected. Version 2025.2.0-alpha.0 contains a fix for this issue.

Affected Software

2 affected components
Misskey Misskey>=12.109.0<2025.2.0-alpha.0
Misskey Misskey>=12.109.0<=2025.1.0

Event History

Feb 11, 2025
CVE Published
via MITRE·03:14 PM
Data Sourced
via MITRE·03:14 PM
DescriptionSeverityWeakness
Oct 3, 57112
Event
via FIRST·08:38 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-24896?

CVE-2025-24896 is considered a medium severity vulnerability due to improper handling of authentication tokens.

2

How do I fix CVE-2025-24896?

To fix CVE-2025-24896, update Misskey to version 2025.2.0-alpha.0 or later, which properly handles cookie deletion upon logout.

3

What versions of Misskey are affected by CVE-2025-24896?

CVE-2025-24896 affects Misskey versions starting from 12.109.0 up to but not including 2025.2.0-alpha.0.

4

What type of vulnerability is CVE-2025-24896?

CVE-2025-24896 is an authentication vulnerability stemming from improper token management in cookies.

5

Is CVE-2025-24896 a practical attack vector?

Yes, CVE-2025-24896 can potentially allow an attacker to exploit stale authentication tokens after a user logs out.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203