LemmyNet lemmy是LemmyNet组织的一个去中心化的链接聚合与讨论社区平台。 LemmyNet lemmy 0.19.19-beta.1之前版本存在跨站脚本漏洞,该漏洞源于Markdown渲染时未对插件生成的输出进行清理和转义,特制alt文本可被注入为实时HTML,可能导致跨站脚本攻击,暴露用户会话并执行经过身份验证的操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54739 | 6.9 MEDIUM | Lemmy: Login Endpoint User Enumeration via HTTP Response Code Differential |
| CVE-2026-54740 | 6.5 MEDIUM | Lemmy: Lower-ranked federated moderator can remove higher-ranked moderators |
| CVE-2026-54738 | 6.5 MEDIUM | Lemmy: Rate limit bypass via X-Forwarded-For header spoofing in actix-web ConnectionInfo |
| CVE-2026-54741 | 5.3 MEDIUM | Lemmy: Blocked users can edit private messages sent before the block |
| CVE-2026-54742 | 5.1 MEDIUM | Lemmy: `CollectionAdd::Featured` does not check the post is in the community |
No comments yet