CVE 6.1 MEDIUM

Hollo renders posts received with form elements and allows submission_CVE-2025-53941

6.1 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Description

Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Versions prior to 0.6.5 allow HTML form elements to be submitted, making the software vulnerable to HTML injection. Version 0.6.5 fixes the issue.

Basic Information

ID CVE-2025-53941
Source GitHub_M
Published Jul 17, 2025 at 14:01
Modified Jul 17, 2025 at 14:21

Affected Product

Vendor fedify-dev
Product hollo
Version < 0.6.5
Affected Versions fedify-dev hollo < 0.6.5

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.