(URGENT) Lemmy has an XSS vulnerability in the sidebar

cross-posted from: https://sh.itjust.works/post/923025

lemmy.world is a victim of an XSS attack right now and the hacker simply injected a JavaScript redirection into the sidebar.

It appears the Lemmy backend does not escape HTML in the main sidebar. Not sure if this is also true for community sidebars.

110 points · 5 comments · view on lemmy.world

5 Comments

p03locke@lemmy.dbzer0.com · 8 pts · 3y (4 replies)

Pretend that all HTML needs to be escaped and only disable it on a case-by-case basis.

cdiv@lemmy.blahaj.zone · 5 pts · 3y (1 reply)

And use the Content-Security-Policy header to limit where scripts can load from, just in case you miss escaping HTML somewhere.

Johanno@lemmy.fmhy.ml · 4 pts · 3y (1 reply)

How can these issues still exist? Man we really should rethink how the web is build.

p03locke@lemmy.dbzer0.com · 2 pts · 3y

No, this shit is embarrassing. Nobody should be hit by Bobby Tables.

Lemmy leadership needs to re-think their priorities. They've entered the big leagues and are still pretending they are in the kid's sandbox.