VYPR
Medium severity6.1NVD Advisory· Published Sep 14, 2026

CVE-2026-91146

CVE-2026-91146

Description

Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, allowing remote actors to inject javascript: links. Attackers can deliver federated content with malicious javascript: hrefs that execute in the instance origin when clicked, enabling session hijacking or impersonation of viewers.

Affected products

2
  • Jointakahe/Takahereferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=0.11.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.