Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jointakahe
Jointakahe takahe |
|
| Vendors & Products |
Jointakahe
Jointakahe takahe |
Mon, 14 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, allowing remote actors to inject javascript: links. Attackers can deliver federated content with malicious javascript: hrefs that execute in the instance origin when clicked, enabling session hijacking or impersonation of viewers. | |
| Title | Takahe through 0.11.0 Cross-Site Scripting via javascript: URL Scheme | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-18T17:23:05.905Z
Reserved: 2026-09-14T20:35:45.259Z
Link: CVE-2026-91146
Updated: 2026-09-18T17:17:03.938Z
Status : Received
Published: 2026-09-14T22:16:59.447
Modified: 2026-09-18T18:18:02.967
Link: CVE-2026-91146
No data.
OpenCVE Enrichment
Updated: 2026-09-17T21:45:16Z