We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-46553

@misskey-dev/summaly Redirect Filter Bypass



Description

@misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1, a logic error in the main `summaly` function causes the `allowRedirects` option to never be passed to any plugins, and as a result, isn't enforced. Misskey will follow redirects, despite explicitly requesting not to. Version 5.2.1 contains a patch for the issue.

Reserved 2025-04-24 | Published 2025-05-05 | Updated 2025-05-05 | Assigner GitHub_M


LOW: 2.1CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:P

Problem types

CWE-693: Protection Mechanism Failure

CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

CWE-665: Improper Initialization

CWE-669: Incorrect Resource Transfer Between Spheres

Product status

>= 3.0.1, < 5.2.1
affected

References

github.com/...ummaly/security/advisories/GHSA-7899-w6c4-vqc4

github.com/...ommit/45153b4f08a772c395a13f7a25399dd87ed022ed

cve.org (CVE-2025-46553)

nvd.nist.gov (CVE-2025-46553)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-46553

Support options

Helpdesk Chat, Email, Knowledgebase