CVE detail
CVE-2023-43805 — CVE-2023-43805
Published 2023-10-04 · Modified 2026-06-17 · Vendor nexryai · Product nexkey · Source nvd
HIGH
severity
CVSS-derived band
0.0065
EPSS probability
exploitation probability, 30d
48.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Nexkey is a fork of Misskey, an open source, decentralized social media platform. Prior to version 12.121.9, incomplete URL validation can allow users to bypass authentication for access to the job queue dashboard. Version 12.121.9 contains a fix for this issue. As a workaround, it may be possible to avoid this by blocking access using tools such as Cloudflare's WAF.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References