CVE-2026-47746: CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition in misskey-dev misskey
Misskey versions 12.37.0 and later, but prior to 2026.5.4, contain a time-of-check to time-of-use (TOCTOU) race condition in the JSON-LD signature validation and compaction process. This flaw arises because the JSON-LD parsing context is not consistently shared between signature verification and subsequent processing, potentially allowing fraudulent information to be accepted as valid. The issue has been fixed in version 2026.5.4.
AI Analysis
Technical Summary
Misskey, an open source federated social media platform, is affected by a TOCTOU race condition (CWE-367) in versions 12.37.0 and later up to but not including 2026.5.4. The vulnerability occurs during JSON-LD signature validation and compaction, where the parsing context used for signature verification is not shared with later processing steps. This inconsistency can be exploited by an attacker to have fraudulent activities accepted as valid, causing a loss of data integrity. The vulnerability has a CVSS 4.0 score of 8.9 (high severity). The issue is resolved in version 2026.5.4.
Potential Impact
An attacker can exploit the TOCTOU race condition to have fraudulent JSON-LD data accepted as valid by the platform, leading to a loss of integrity in the system. This could allow unauthorized or malicious activities to be processed as legitimate, undermining trust in the platform's data validation.
Mitigation Recommendations
A fix is available in Misskey version 2026.5.4. Users and administrators should upgrade to this version to remediate the vulnerability. No additional mitigation guidance is provided or required beyond applying the official fix.
CVE-2026-47746: CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition in misskey-dev misskey
Description
Misskey versions 12.37.0 and later, but prior to 2026.5.4, contain a time-of-check to time-of-use (TOCTOU) race condition in the JSON-LD signature validation and compaction process. This flaw arises because the JSON-LD parsing context is not consistently shared between signature verification and subsequent processing, potentially allowing fraudulent information to be accepted as valid. The issue has been fixed in version 2026.5.4.
CVSS v4.0
Score 8.9high
Affected software
pkg:github/misskey-dev/misskeyRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Misskey, an open source federated social media platform, is affected by a TOCTOU race condition (CWE-367) in versions 12.37.0 and later up to but not including 2026.5.4. The vulnerability occurs during JSON-LD signature validation and compaction, where the parsing context used for signature verification is not shared with later processing steps. This inconsistency can be exploited by an attacker to have fraudulent activities accepted as valid, causing a loss of data integrity. The vulnerability has a CVSS 4.0 score of 8.9 (high severity). The issue is resolved in version 2026.5.4.
Potential Impact
An attacker can exploit the TOCTOU race condition to have fraudulent JSON-LD data accepted as valid by the platform, leading to a loss of integrity in the system. This could allow unauthorized or malicious activities to be processed as legitimate, undermining trust in the platform's data validation.
Mitigation Recommendations
A fix is available in Misskey version 2026.5.4. Users and administrators should upgrade to this version to remediate the vulnerability. No additional mitigation guidance is provided or required beyond applying the official fix.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-19T22:16:39.504Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a71103cbf32cb7a344d9fc1
Added to database: 08/03/2026, 22:03:40 UTC
Last enriched: 08/03/2026, 22:17:51 UTC
Last updated: 08/04/2026, 01:02:28 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.