CVE-2026-46713
Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD signature validation and compaction process that allows spoofed activities to be accepted as valid. This issue has been fixed in version 2026.5.4.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/misskey-dev/misskey/releases/tag/2026.5.4, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46713.json, https://github.com/misskey-dev/misskey/security/advisories/GHSA-w8x2-gpq6-jxvf, https://nvd.nist.gov/vuln/detail/CVE-2026-46713