We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
@misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1, a logic error in the main `summaly` function causes the `allowRedirects` option to never be passed to any plugins, and as a result, isn't enforced. Misskey will follow redirects, despite explicitly requesting not to. Version 5.2.1 contains a patch for the issue.
Reserved 2025-04-24 | Published 2025-05-05 | Updated 2025-05-05 | Assigner GitHub_MCWE-693: Protection Mechanism Failure
CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CWE-665: Improper Initialization
CWE-669: Incorrect Resource Transfer Between Spheres
github.com/...ummaly/security/advisories/GHSA-7899-w6c4-vqc4
github.com/...ommit/45153b4f08a772c395a13f7a25399dd87ed022ed
Support options