Skip Navigation
Update to the lemmy.world hack, blahaj also hacked, maybe huge lemmy exploit?
sh.itjust.works (URGENT) Lemmy has an XSS vulnerability in the tagline, the sidebar and in the legal information field - sh.itjust.works

# DO NOT OPEN THE “LEGAL” PAGE — lemmy.world is a victim of an XSS attack right now and the hacker simply injected a JavaScript redirection into the sidebar. It appears the Lemmy backend does not escape HTML in the main sidebar. Not sure if this is also true for community sidebars. [https://sh.itjus...

I don't really understand what any of this means, maybe someone can explain it for me, I'm a little nervous to keep browsing on lemmygrad if this can apparently be exploited thru comments and posts or something?

there's disagreement about what's happening several comments down so an explanation would be appreciated

0
Lemmy.world compromised
lemmygrad.ml PSA: Lemmy.world has been compromised! (Edit: Multiple Instances are down) - Lemmygrad

FYI!!! In case you start getting re-directed to porn sites. Maybe the admin got hacked? --------- edit: lemmy.blahaj.zone has also been hacked. beehaw.org [http://beehaw.org] is also down, possibly intentionally by their admins until the issue is fixed. Post discussing the point of vulnerability: ht...

Supposedly randomly redirecting to porn or gore sites, some racist vandalism even if you don’t get redirected, screenshot in the comments.

Edit: comments saying it might already be getting fixed, glad they got on top of it quickly.

0
InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)IM
ImOnADiet [he/him] @hexbear.net
Posts 2
Comments 2