CVE-2023-49095: Nexryai Nexkey
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
nexkey is a microblogging platform. Insufficient validation of ActivityPub requests received in inbox could allow any user to impersonate another user in certain circumstances. This issue has been patched in version 12.122.2.
Affected products
- Nexryai Nexkey: before 12.122.2 (fixed in 12.122.2)
Published 2023-11-30. Last modified 2026-06-17.