CVE-2026-91146
Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, allowing remote actors to inject javascript: links. Attackers can deliver federated content with malicious javascript: hrefs that execute in the instance origin when clicked, enabling session hijacking or impersonation of viewers.
- Published Sep 14, 2026
- CVSS 5.3 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)