GHSA-p8xj-r4q8-q652MediumCVSS 6.1

Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content...

Published
September 15, 2026
Last Modified
September 15, 2026

🔗 CVE IDs covered (1)

📋 Description

Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, allowing remote actors to inject javascript: links. Attackers can deliver federated content with malicious javascript: hrefs that execute in the instance origin when clicked, enabling session hijacking or impersonation of viewers.

🔗 References (6)