this post was submitted on 10 Jul 2023
75 points (100.0% liked)

Fediverse

8 readers
2 users here now

This magazine is dedicated to discussions on the federated social networking ecosystem, which includes decentralized and open-source social media platforms. Whether you are a user, developer, or simply interested in the concept of decentralized social media, this is the place for you. Here you can share your knowledge, ask questions, and engage in discussions on topics such as the benefits and challenges of decentralized social media, new and existing federated platforms, and more. From the latest developments and trends to ethical considerations and the future of federated social media, this category covers a wide range of topics related to the Fediverse.

founded 2 years ago
 

Lemmy.world and lemmy.blahaj.zone have been hit with a JavaScript injection attack it seems.

you are viewing a single comment's thread
view the rest of the comments
[โ€“] [email protected] 13 points 1 year ago (1 children)

Looks like Lemmy code has a security vulnerability, persistent XSS, that allows injection of Javascript into the sidebar and comments. That allowed the attacker to force load NSFW content even after lemmy.world admins cleaned up the first attack.

Looks like the injected JS code also steals login tokens from your browser, seems some admin accounts got compromised this way.
Probably a good idea to not visit Lemmy sites for time being (or block execution of Javascript in your browser, which is always a good idea).

[โ€“] [email protected] 2 points 1 year ago

Not just sidebar or comments, but anywhere markdown is used. The issue is the markdown editor. This is the current proposed fix.