Description
After adding private posts (followers, direct) that you do not have permission to view to your favorites or clips, you can export them to view the contents of the private posts.
Recommendation
Update the misskey-js package to the latest compatible version. Followings are version details:
- Affected version(s): >= 13.0.0-beta.16, < 2025.12.0
- Patched version(s): 2025.12.0
References
Could your website be exposed too?
SmartScanner can check your website for misskey.js's export data contains private post data and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Misskey has a login rate limit bypass via spoofed X-Forwarded-For header - CVE-2025-66482
- Bootstrap Multiselect Vulnerable to CSRF and Reflective XSS via Arbitrary POST Data - CVE-2025-47204
- @clerk/backend Performs Insufficient Verification of Data Authenticity - CVE-2025-53548
- [email protected] contains malware after npm account takeover - CVE-2025-59142
You might also like:
See something that needs correcting? Let us knowUpdated January 06, 2026


