lemmy.world is a victim of an XSS attack right now and the hacker simply injected a JavaScript redirection into the sidebar.

It appears the Lemmy backend does not escape HTML in the main sidebar. Not sure if this is also true for community sidebars.

EDIT: as a demo, your web browser is probably telling you that it’s blocked a popup or something, you should see an alert I’ve injected

    • oce 🐆@jlai.lu
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      1 year ago

      The pilot crashed on the field because the helicopter was misfunctioning, and it risked falling on a primary school.