{"id":"CVE-2026-57574","title":"Misskey is an open source, federated social media platform","summary":"Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a vulnerability in Time-based One-Time Password (TOTP) authentication in UserAuthService where insufficient validation of used tokens allows …","severity":"none","cwe":["CWE-294"],"published":"2026-07-10","updated":"2026-07-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-57574","references":[{"url":"https://github.com/misskey-dev/misskey/commit/00c6210a591db2b0be438740d05b82070fa68ac6","label":"security-advisories@github.com"},{"url":"https://github.com/misskey-dev/misskey/commit/d323fe00d04ac46ab0b4e66fce9169effaa8dfb7","label":"security-advisories@github.com"},{"url":"https://github.com/misskey-dev/misskey/releases/tag/2026.6.0","label":"security-advisories@github.com"},{"url":"https://github.com/misskey-dev/misskey/security/advisories/GHSA-2m5x-5mp6-6vpq","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00551,"epssPercentile":0.44987,"ingestedAt":"2026-07-11T20:15:27.380Z","slug":"CVE-2026-57574","body":"## Overview\n\nMisskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a vulnerability in Time-based One-Time Password (TOTP) authentication in UserAuthService where insufficient validation of used tokens allows the reuse of a single-use code within its valid time step. If both credentials and a TOTP code are obtained concurrently, an attacker may reuse the code to perform unauthorized actions, potentially leading to account takeover. This issue is fixed in version 2026.6.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}