🚨🚨 Update your Kbin instance now! 🚨🚨

Dear kbin server owners, upgrade your Kbin instance now! Ernest just merged a critical hot fix into the develop branch.

If you don't update, your Kbin instance is vulnerable for HTML/JS injection. Which allows bad actors to do very nasty things on your instance and attack your visitors on your site.

Commit: https://codeberg.org/Kbin/kbin-core/commit/8ee87ba9fbb3192865dfebb054bec3da56b9493e

65 points · 10 comments · view on lemmy.world

10 Comments

sarsaparilyptus@lemmy.fmhy.ml · 30 pts · 3y (4 replies)

Thanks the hot tip, I'm attacking eveny kbin instance while I still can!

melroy@kbin.melroy.org · 15 pts · 3y

Thanks you for your compassion.

melroy@kbin.melroy.org · 1 pts · 3y (2 replies)

@sarsaparilyptus Lemmy got hacked..

sarsaparilyptus@lemmy.fmhy.ml · 1 pts · 3y (1 reply)

That wasn't me, I was in the comfort of my living room jacking it to Sonic R34 all night last night

melroy@kbin.melroy.org · 1 pts · 3y

@sarsaparilyptus too much info

Mic_Check_One_Two@lemmy.world · 3 pts · 3y (2 replies)

Honestly, the fact that kbin was open to injection attacks in the first place is hilarious. That’s like day 1 cybersecurity training.

Anyone have the Bobby Tables xkcd handy?

Edit: Found it.

melroy@kbin.melroy.org · 3 pts · 3y

@Mic_Check_One_Two Actually it was just since recently the case. Kbin used to escape the content, of course.. But after an upgrade to a newer Markdown parser version, it was overlooked in a PR.

We are recently approved for the Codeberg CI, hopefully allowing us to setup a good CI/CD pipeline. Avoiding these kind of regressions in the first place. Kbin is still in beta.

melroy@kbin.melroy.org · 1 pts · 3y

@Mic_Check_One_Two Oopsy.. now lemmy.world is hacked.

Putykat@lemmy.world · 1 pts · 3y
[ removed ]