GHSA-p8xj-r4q8-q652MediumCVSS 6.1
Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content...
🔗 CVE IDs covered (1)
📋 Description
Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, allowing remote actors to inject javascript: links. Attackers can deliver federated content with malicious javascript: hrefs that execute in the instance origin when clicked, enabling session hijacking or impersonation of viewers.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-91146
- https://github.com/jointakahe/takahe/issues/728
- https://github.com/jointakahe/takahe
- https://github.com/jointakahe/takahe/blob/0.11.0/core/html.py
- https://www.vulncheck.com/advisories/takahe-through-0.11.0-cross-site-scripting-via-javascript-url-scheme
- https://github.com/advisories/GHSA-p8xj-r4q8-q652