Impact
Takahe versions up to 0.11.0 permit the injection of "javascript:" URLs in link hrefs that appear in federated posts and profile summaries. When a user clicks such a link, the JavaScript executes with the origin of the instance, potentially hijacking the user’s session or impersonating the viewer. The vulnerability is a typical reflected or stored cross‑ schemes (CWE‑79).
Affected Systems
The affected product is Takahe developed by jointakahe, and all releases through version 0.11.0 are susceptible. Any instance of Takahe running 0.11.0 or earlier without a security update is at risk. Followers, custom instances, or any federated content provider can be the source of malicious links.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity; the EPSS score is approximately 0.00194, which is less than 1%, and the vulnerability is not listed in CISA’s KEV catalogue. The flaw can be exploited by an attacker who can send federated content or compromise the profile summary of a target instance. No local privilege escalation or complex prerequisite is required; the attack vector is remote, directed at the application’s handling of user‑supplied URLs. Given the lack of an existing exploit listing, the direct risk is limited, but the potential for session hijacking keeps the vulnerability relevant for actively federated instances.
OpenCVE Enrichment