PT-2026-91744 · Takahe · Takahe
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Takahe versions prior to 0.11.1
Description
The software fails to restrict URL schemes in link hrefs within federated post content and profile summaries. This allows remote actors to inject
javascript: links. When clicked, these malicious links execute in the instance origin, which can lead to session hijacking or the impersonation of viewers.Recommendations
Update Takahe to version 0.11.1 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Takahe