TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Lemmy has an XSS vulnerability in the Markdown parser

7 点作者 hardcopy将近 2 年前

2 条评论

xyst将近 2 年前
What a blunder.<p>I think even the worst static code analyzers would have caught this.<p>Looking at the code that was injected by an attacker it seems like they were trying to extract user sessions and exfiltrate it.<p><a href="https:&#x2F;&#x2F;programming.dev&#x2F;post&#x2F;532566" rel="nofollow noreferrer">https:&#x2F;&#x2F;programming.dev&#x2F;post&#x2F;532566</a>
urda将近 2 年前
I found myself asking the same thing: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=36662195">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=36662195</a>