Remote View InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)ME meta @lemmygrad.ml CannotSleep420 @lemmygrad.ml 2y ago (URGENT) Lemmy has an XSS vulnerability in the sidebar cross-posted from: https://sh.itjust.works/post/923025 lemmy.world is a victim of an XSS attack right now and the hacker simply injected a JavaScript redirection into the sidebar. It appears the Lemmy backend does not escape HTML in the main sidebar. Not sure if this is also true for community sidebars.