cross-posted from: https://sh.itjust.works/post/923025
lemmy.world is a victim of an XSS attack right now and the hacker simply injected a JavaScript redirection into the sidebar.
It appears the Lemmy backend does not escape HTML in the main sidebar. Not sure if this is also true for community sidebars.

5 Comments
p03locke@lemmy.dbzer0.com · 8 pts · 3y
Pretend that all HTML needs to be escaped and only disable it on a case-by-case basis.
cdiv@lemmy.blahaj.zone · 5 pts · 3y
And use the Content-Security-Policy header to limit where scripts can load from, just in case you miss escaping HTML somewhere.
p03locke@lemmy.dbzer0.com · 3 pts · 3y
They did, but then they turned those protections off, lol
Johanno@lemmy.fmhy.ml · 4 pts · 3y
How can these issues still exist? Man we really should rethink how the web is build.
p03locke@lemmy.dbzer0.com · 2 pts · 3y
No, this shit is embarrassing. Nobody should be hit by Bobby Tables.
Lemmy leadership needs to re-think their priorities. They've entered the big leagues and are still pretending they are in the kid's sandbox.