TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Lemmy has an XSS vulnerability in the Markdown parser

7 pointsby hardcopyalmost 2 years ago

2 comments

xystalmost 2 years ago
What a blunder.<p>I think even the worst static code analyzers would have caught this.<p>Looking at the code that was injected by an attacker it seems like they were trying to extract user sessions and exfiltrate it.<p><a href="https:&#x2F;&#x2F;programming.dev&#x2F;post&#x2F;532566" rel="nofollow noreferrer">https:&#x2F;&#x2F;programming.dev&#x2F;post&#x2F;532566</a>
urdaalmost 2 years ago
I found myself asking the same thing: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=36662195">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=36662195</a>