Be careful what posts you click until this is patched.

EDIT: Clarify, this server I expect is also vulnerable, hence the choice of community.

  • @21trillionsats
    link
    English
    41 year ago

    Hits a 404 now on the link (sh.itjust.works link above), does anyone have a TLDR?

    • @henfredemarsOP
      link
      English
      9
      edit-2
      1 year ago

      Deleting the post might have been damage control because the disclosure was not responsible. Details are in the project GitHub, but basically it’s possible to trick Lemmy into serving injected JavaScript by making a post with a crafted URL.

      This could allow a user to compromise the accounts of other users if you can get them to click on your post.

  • udunadan
    link
    English
    11 year ago

    deleted by creator

  • Vashtea
    link
    fedilink
    English
    11 year ago

    I use “top day” when this happens to me.(jerboa)

  • udunadan
    link
    English
    11 year ago

    deleted by creator