What is Nostr?
Oneesan succubus /
npub12ha…xxk6
2023-05-26 18:29:58

Oneesan succubus on Nostr: Alright, we found a second exploit that is much worse than the first one I found, it ...

Alright, we found a second exploit that is much worse than the first one I found, it involves a bug in our oembed parser. A new release is being prepared right now. Unless there's a third exploit, this can be mitigated by disabling rich media in the pleroma settings. Frontends other than pleroma-fe might also be not vulnerable.

What alex is recommending here will also fix the issue, so you can do that as well:

https://gleasonator.com/notice/AW3PsTi4WCWEUbN0uO
Author Public Key
npub12haw8lqt6g57r8zk9vc7w32cezuu2d5tcqpsarquntgfl5n0wrjq8nxxk6