Hey, guys.
Pre-workday-Netto chiming in to inform you that a XSS vulnerability has been found in Lemmy’s frontend and that several instances have been compromised.
You can track the issue here.
I implemented the supposed patch and uploaded an ARM64 build that has the patch applied to Docker Hub, if any other instance might need it (use with caution).
Please note that you’ll have to log back in, as all active sessions have been terminated.
I’ll continue to monitor the situation when I’m at work.
✌️
That’s great. A static page where you can post a short message in case of an outage would be nice to have as well.