CVE-2025-61775

Vickey is a Misskey-based microblogging platform. A vulnerability exists in Vickey prior to version 2025.10.0 where unexpired email confirmation links can be reused multiple times to send repeated confirmation emails to a verified email address. Under certain conditions, a verified email address could receive repeated confirmation messages if the verification link was accessed multiple times. This issue may result in unintended email traffic but does not expose user data. The issue was addressed in version 2025.10.0 by improving validation logic to ensure verification links behave as expected after completion.
CVSS

No CVSS.

Configurations

No configuration.

History

13 Oct 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-13 18:15

Updated : 2025-10-14 19:36


NVD link : CVE-2025-61775

Mitre link : CVE-2025-61775

CVE.ORG link : CVE-2025-61775


JSON object : View

Products Affected

No product.

CWE
CWE-613

Insufficient Session Expiration

CWE-770

Allocation of Resources Without Limits or Throttling