Junglewise Threat Intelligence

CVE-2025-66402: Misskey.js export data contains private post data

CVE-2025-66402 · Severity: low · CVSS 3.1 · Published 2025-12-15

Vendors: npm, Misskey-Dev.

Executive brief

Misskey.js is a JavaScript library for interacting with Misskey, a social media platform similar to Mastodon. When users export their favorites or clips, the exported data can inadvertently include the full content of private posts (restricted to followers or specific users) that the exporting user should not have permission to view. An attacker who can add private posts to their favorites or clips can export and read content they shouldn't have access to, potentially exposing sensitive communications or pinned private posts.

Technical details

The vulnerability exists in Misskey.js's export functionality for user favorites and clips. The root cause is insufficient authorization checks when exporting post data—the export routine fails to validate whether the exporting user has permission to view the posts being exported. An attacker can add private posts (followers-only or directed to specific users) to their favorites or clips by referencing their URLs, then export the collection to retrieve the full post content without proper access control. The attack requires authentication and network access but no user interaction beyond the export action. The vulnerability was fixed in Misskey version 2025.12.0. CWE-862 (Missing Authorization) is the underlying weakness.

Affected products

  • Misskey-dev misskey-js >=13.0.0-beta.16, <2025.12.0

Timeline

  • 2025-12-15: disclosed
  • 2025-12-01: patched: Fix available in version 2025.12.0

References

Related threats