I am not a super code-literate person so bare with me on this… But. Still please becareful. There appears to be a vulnerability.
Users are posting images like the following:
And inside hidden is JavaScript code that when executed can take cookie information and send it to a URL address.
Among other things. At this time if you see an image please click the icon circled before clicking the link. DO NOT CLICK THE IMAGE. If you see anything suspicious, please report it immediately. It is better a false report than a missed one.
Doesn’t affect my mobile client
deleted by creator
If anything this is probably a vulnerability in a browser implementation (or one of the apps). I’d be surprised if Lemmy in and of itself is vulnerable to an attack via embedded JS in a picture.
No offense, but I think you’re putting too much trust on the Lemmy code. I’m not saying the code is bad, but it’s just as likely as other codes that the vulnerability is in Lemmy’s code.
But lemmy itself shouldn’t really interact with the images in terms of decoding them. Just having the code in the image may be weird but it should only affect code that actually tries to read and understand the bytes. Just passing it around shouldn’t cause the code to be executed.
And the real decoding and displaying is hopefully done by the browsers Codebase, not by anything Lemmy does itself.
At least that’s my line of reasoning. I may very well be off here.