CVE-2025-24900
Last modified
CVE-2025-24900 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Due to a lack of CSRF countermeasures and improper settings of cookies for MediaProxy authentication, there is a vulnerability that allows MediaProxy authentication to be bypassed. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Due to a lack of CSRF countermeasures and improper settings of cookies for MediaProxy authentication, there is a vulnerability that allows MediaProxy authentication to be bypassed. In versions prior to 12.25Q1.1, the authentication cookie does not have the SameSite attribute. This allows an attacker to bypass MediaProxy authentication and load any image without restrictions under certain circumstances. In versions prior to 12.24Q2.3, this cookie was also used to authenticate the job queue management page (bull-board), so bull-board authentication is also bypassed. This may enable attacks that have a significant impact on availability and integrity. The affected versions are too old to be covered by this advisory, but the maintainers of Concorde strongly recommend not using older versions. Version 12.25Q1.1 contains a patch. There is no effective workaround other than updating.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-24900?
How severe is CVE-2025-24900?
How do I fix CVE-2025-24900?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-24895CIE.AspNetCore.Authentication is an AspNetCore Remote Authen…9.1
- CVE-2025-24896Misskey is an open source, federated social media platform. …8.1
- CVE-2025-24897Misskey is an open source, federated social media platform. …8.2
- CVE-2025-24898rust-openssl is a set of OpenSSL bindings for the Rust progr…6.3
- CVE-2025-24899reNgine is an automated reconnaissance framework for web app…7.5
- CVE-2025-2490A vulnerability was found in Dromara ujcms 9.7.5. It has bee…5.4
- CVE-2025-24901WeGIA is a Web Manager for Charitable Institutions. A SQL In…8.8
- CVE-2025-24902WeGIA is a Web Manager for Charitable Institutions. A SQL In…8.8
- CVE-2025-24903libsignal-service-rs is a Rust version of the libsignal-serv…8.5
- CVE-2025-24904libsignal-service-rs is a Rust version of the libsignal-serv…8.5
- CVE-2025-24905WeGIA is a Web Manager for Charitable Institutions. A SQL In…9.8
- CVE-2025-24906WeGIA is a Web Manager for Charitable Institutions. A SQL In…9.8
Are you affected by CVE-2025-24900?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
