Vulnerability Description
Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a vulnerability in Time-based One-Time Password (TOTP) authentication in UserAuthService where insufficient validation of used tokens allows the reuse of a single-use code within its valid time step. If both credentials and a TOTP code are obtained concurrently, an attacker may reuse the code to perform unauthorized actions, potentially leading to account takeover. This issue is fixed in version 2026.6.0.
Related Weaknesses (CWE)
References
- https://github.com/misskey-dev/misskey/commit/00c6210a591db2b0be438740d05b82070f
- https://github.com/misskey-dev/misskey/commit/d323fe00d04ac46ab0b4e66fce9169effa
- https://github.com/misskey-dev/misskey/releases/tag/2026.6.0
- https://github.com/misskey-dev/misskey/security/advisories/GHSA-2m5x-5mp6-6vpq
FAQ
What is CVE-2026-57574?
CVE-2026-57574 is a documented vulnerability. Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a vulnerability in Time-based One-Time Password (TOTP) authentication in UserAuthService where insuffici...
How severe is CVE-2026-57574?
CVSS scoring is not yet available for CVE-2026-57574. Check NVD for updates.
Is there a patch for CVE-2026-57574?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.