Executive brief
@misskey-dev/summaly is a JavaScript library used to generate previews of web content linked in Misskey social media posts. A logic error prevents the redirect filter setting from being enforced, allowing the library to follow HTTP redirects even when explicitly configured not to do so. This could enable attackers to trick users into previewing malicious sites by redirecting from innocuous URLs.
Technical details
The vulnerability is a logic error (CWE-664) in the main summaly function where a new scrapingOptions object is created and passed to plugins, but the allowRedirects property from the original opts parameter is not copied over. As a result, the redirect filtering configuration is lost and not enforced. The attack is network-based, requires no authentication, but does require user interaction (posting a link in Misskey). An attacker can create a link that redirects to a different target, and despite the application requesting no redirects, the library will follow the redirect and generate a preview of the final destination. The vulnerability was fixed in version 5.2.1.
Affected products
- misskey-dev summaly >=3.0.1, <5.2.1
Timeline
- 2025-05-05: disclosed
- 2025-05-05: patched: Fixed in version 5.2.1