CVE-2025-24897 | misskey-dev misskey prior 2025.2.0-alpha.0 Web Application Firewall /queue cross-site request forgery (GHSA-38w6-vx8g-67pp)
A vulnerability was found in misskey-dev misskey. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /queue of the component Web Application Firewall. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2025-24897. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.