Vulnerability Description
Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, allowing remote actors to inject javascript: links. Attackers can deliver federated content with malicious javascript: hrefs that execute in the instance origin when clicked, enabling session hijacking or impersonation of viewers.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/jointakahe/takahe
- https://github.com/jointakahe/takahe/blob/0.11.0/core/html.py
- https://github.com/jointakahe/takahe/issues/728
- https://www.vulncheck.com/advisories/takahe-through-0.11.0-cross-site-scripting-
FAQ
What is CVE-2026-91146?
CVE-2026-91146 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, allowing remote actors to inject javascript: links. Attackers can deliver federat...
How severe is CVE-2026-91146?
CVE-2026-91146 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-91146?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.