Thank you. I was bewildered by the earlier announcement but you have laid it out a lot clearer here.
Sorry about that, it took us a while to figure out what was going on!
At the end of the day we're a community project, not a commercial one, so we don't have full time sysadmin hands on deck 24/7 etc. (But ultimately I think this is totally fine for what we are! And ultimately non-commercial is more sustainable for online communities IMO)
I'm sorry if my statement cause you any confusion (シ_ _)シ
No wonder I couldn't see the posts from here today from my instance. Anyway RC2 is out, which should fix this XSS vulnerability
Ah, didn't realize there's a site sticky. Sorry about the other post. Everyone pening dealing with this ig. Sucks to not be on PC.
Still not sure if comments loaded from other instances with custom emoji (the vector of this exploit) can trigger the exploit here, but since we defederated there shouldn't be a way for it to get in, I hope.
No problemo. Seriously, thanks for the concern! And yeah we think we're as safe as we can make us for the time being.
Announcements