### [CVE-2019-1020010](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1020010) ![](https://img.shields.io/static/v1?label=Product&message=Misskey&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=hijacking%20a%20user's%20token&color=brighgreen) ### Description Misskey before 10.102.4 allows hijacking a user's token. ### POC #### Reference - https://github.com/syuilo/misskey/security/advisories/GHSA-6qw9-6jxq-xj3p #### Github - https://github.com/Calistamu/graduation-project - https://github.com/DXY0411/CVE-2019-1020010