Medium severity6.1NVD Advisory· Published Sep 14, 2026
CVE-2026-91146
CVE-2026-91146
Description
Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, allowing remote actors to inject javascript: links. Attackers can deliver federated content with malicious javascript: hrefs that execute in the instance origin when clicked, enabling session hijacking or impersonation of viewers.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=0.11.0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.