Junglewise Threat Intelligence

CVE-2026-57575: Misskey SSRF in UrlPreviewService

CVE-2026-57575 · Severity: info · CVSS 6.9 · Published 2026-07-10

Vendors: Misskey-Dev.

Executive brief

Misskey is an open-source, decentralized social media platform. A security flaw in its link preview feature allows the server to be tricked into making unauthorized requests to internal network services, such as private databases or local administrative interfaces. While current evidence suggests sensitive data is not leaked back to the attacker, this could be used to probe internal infrastructure or interact with unprotected internal systems.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the UrlPreviewService of Misskey due to insufficient network restrictions before establishing outbound connections. The application fails to validate destination IP addresses prior to initiating HTTP requests, allowing an attacker to target loopback, private, or link-local addresses (e.g., 127.0.0.1 or 169.254.169.254). Although the server performs validation after the request is sent and rejects the response, an attacker can still trigger outbound traffic to internal services. This issue is resolved in version 2026.6.0 by implementing proper pre-request network filtering.

Affected products

  • misskey-dev Misskey < 2026.6.0

Timeline

  • 2026-06-22: patched: Version 2026.6.0 released
  • 2026-07-02: disclosed: GitHub Security Advisory published
  • 2026-07-10: advisory: NVD published CVE-2026-57575

References