losttourist, (edited )
@losttourist@social.chatty.monster avatar

Edit: there is now a mitigation available. It should be safe to use Lemmy again as long as your instance has applied the fix.

https://lemmy.world/post/1293336

Yep, it looks like there is a XSS vulnerability with Lemmy that has been widely exploited, allowing the attackers to steal cookie credentials including potentially those of the site admins.

Some other non-compromised Lemmy instances have taken themselves offline until a fix is available.

Kbin is not affected as far as I can see.

If you have a Lemmy account, don't use it at the moment!

lispi314,
@lispi314@mastodon.top avatar

@losttourist Yet another reason to not enable Javascript support and to not require it in any program.

zzt,
@zzt@mas.to avatar

@losttourist mind quoting the mitigation here? given the chatter on GitHub I’m a bit paranoid that the issue hasn’t been fixed completely, but lemmy.world seems to be the only source for the mitigation

losttourist,
@losttourist@social.chatty.monster avatar

@zzt That lemmy.world post with instructions to admins to delete custom emojis is all I have.

As far as I understand it, the XSS vuln was in the hover text for custom emojis, so presumably no custom emojis = no dodgy scripts.

But that's all I have. Note that I'm not a Lemmy developer, admin or even a Lemmy user - just a concerned & interested fediverse citizen trying to help keep people safe.

zzt,
@zzt@mas.to avatar

@losttourist makes sense! I appreciate you doing this — outreach and messaging from lemmy’s devs hasn’t been ideal

PhilipKing,
@PhilipKing@mastodon.social avatar

@losttourist Probably too early to speculate but I wonder who is behind it?

losttourist,
@losttourist@social.chatty.monster avatar

@PhilipKing No idea, but apparently after gaining access to an admin's account on lemmy.world they defaced the site with porn and racist slogans. So probably just script kiddies rather than anything more organised.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • fediverse
  • GTA5RPClips
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • tacticalgear
  • cubers
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • osvaldo12
  • ngwrru68w68
  • kavyap
  • InstantRegret
  • JUstTest
  • everett
  • Durango
  • cisconetworking
  • khanakhh
  • ethstaker
  • tester
  • anitta
  • Leos
  • normalnudes
  • modclub
  • megavids
  • provamag3
  • lostlight
  • All magazines