PatchSiren cyber security CVE debrief
CVE-2026-91146 jointakahe CVE debrief
CVE-2026-91146 debrief: Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, allowing remote actors to inject javascript: links. This vulnerability enables attackers to deliver federated content with malicious javascript: hrefs that execute in the instance origin when clicked, potentially leading to session hijacking or impersonation of viewers. Defenders should assess exposure and prioritize verification and remediation efforts.
- Vendor
- jointakahe
- Product
- takahe
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-14
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-14
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for Takahe instances, particularly those with federated content and profile summaries, should assess exposure and prioritize verification and remediation efforts. This includes reviewing instance configurations, monitoring for suspicious activity, and implementing compensating controls. Security teams and vulnerability management teams should also prioritize this vulnerability and coordinate with affected operators and platforms.
Why it matters
CVE-2026-91146 allows remote actors to inject malicious javascript: links in federated post content and profile summaries, enabling session hijacking or impersonation of viewers. Defenders should prioritize verifying and updating Takahe instances.
- Session hijacking or impersonation of viewers who click on malicious links
- Potential for unauthorized actions within the instance origin
- Need for verification of affected versions and instances
- Prioritization of remediation and compensating controls
Technical summary
Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, allowing remote actors to inject javascript: links that execute in the instance origin when clicked. This vulnerability enables attackers to deliver malicious content that can lead to session hijacking or impersonation of viewers. The vulnerability is related to the handling of federated post content and profile summaries in Takahe instances. Defenders should prioritize verifying and updating Takahe instances to prevent exploitation.
Defensive priority
Defenders should prioritize verifying and updating Takahe instances to prevent exploitation of this vulnerability.
Recommended defensive actions
- Verify and update Takahe instances to the latest version
- Restrict URL schemes in link hrefs within federated post content and profile summaries
- Monitor for suspicious activity and implement compensating controls
- Review instance configurations and content for potential exposure
- Prioritize remediation and compensating controls for exposed instances
- Track exceptions and retest remediated assets
- Implement additional security measures to prevent session hijacking and impersonation
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but the scope of affected versions and instances requires further verification. The vulnerability affects Takahe instances with federated content and profile summaries. Defenders should verify and update Takahe instances to prevent exploitation. Evidence is limited, and further review of instance configurations and content is necessary.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-91146 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-91146
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-91146 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-91146
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/jointakahe/takahe
-
Source reference
Unverified legacy reference
URL: https://github.com/jointakahe/takahe/blob/0.11.0/core/html.py
-
Source reference
Unverified legacy reference
URL: https://github.com/jointakahe/takahe/issues/728
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/takahe-through-0.11.0-cross-site-scripting-via-javascript-url-scheme
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.