Misskey is an open source, decentralized social media platform. In versions before 13.3.3 SQL injection is possible due to insufficient parameter validation in the note search API by tag (notes/search-by-tag). This has been fixed in version 13.3.3. Users are advised to upgrade. Users unable to upgrade should block access to the `api/notes/search-by-tag` endpoint.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
misskey misskey |