Skip Navigation
Lemmy.ca's Main Community @lemmy.ca AlternateRoute @lemmy.ca

(URGENT) Lemmy has an XSS vulnerability in the sidebar

cross-posted from: https://sh.itjust.works/post/923025

lemmy.world is a victim of an XSS attack right now and the hacker simply injected a JavaScript redirection into the sidebar.

It appears the Lemmy backend does not escape HTML in the main sidebar. Not sure if this is also true for community sidebars.

43

You're viewing a single thread.

43 comments
  • someone must be protesting lemmy if they are blocking the site and redirecting to NSFW

    who has demonstrated use of that modus operandi ? /ponder

    lmfaooooooo

    • why is your entire account dedicated to sucking reddit's asshole. do you like the taste of corporate shit?

      • Yeah it's so weird, why make an account here if he likes Reddit so much? We just want to have another place to have communities, that's why we left and stayed here. He should do the same, stay there and out of here if he hates this place so much.

        • it's honestly pathetic. he hates it here so much that he spends 95% of his free time here making comments about how much better reddit is hahaha. he seems addicted to this place and addicted to the taste of shiny black boots

          • I mean I get that he's in some sort of one-way findom relationship with spez but that should be done without harassing other people— we didn't consent to it.

You've viewed 43 comments.