Skip to main content

CVE-2025-53941: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in fedify-dev hollo

Medium
VulnerabilityCVE-2025-53941cvecve-2025-53941cwe-79
Published: Thu Jul 17 2025 (07/17/2025, 14:01:34 UTC)
Source: CVE Database V5
Vendor/Project: fedify-dev
Product: hollo

Description

Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Versions prior to 0.6.5 allow HTML form elements to be submitted, making the software vulnerable to HTML injection. Version 0.6.5 fixes the issue.

Technical Details

Data Version
5.1
Assigner Short Name
GitHub_M
Date Reserved
2025-07-14T17:23:35.262Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 687905aba83201eaace63c5e

Added to database: 7/17/2025, 2:16:11 PM

Last updated: 7/17/2025, 2:16:11 PM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats