CVE-2025-53941 – Hollo ActivityPub HTML Injection Vulnerability

The following table lists the changes that have been made to the
CVE-2025-53941 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • CVE Modified
    by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jul. 17, 2025

    Action Type Old Value New Value
    Added Reference https://github.com/fedify-dev/hollo/security/advisories/GHSA-w7gc-g3x7-hq8h
  • New CVE Received
    by [email protected]

    Jul. 17, 2025

    Action Type Old Value New Value
    Added Description Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Versions prior to 0.6.5 allow HTML form elements to be submitted, making the software vulnerable to HTML injection. Version 0.6.5 fixes the issue.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
    Added CWE CWE-79
    Added Reference https://github.com/fedify-dev/hollo/commit/f9d25e10ba5406c27f9e87dfb01f75b6a52f2410
    Added Reference https://github.com/fedify-dev/hollo/releases/tag/0.6.5
    Added Reference https://github.com/fedify-dev/hollo/security/advisories/GHSA-w7gc-g3x7-hq8h
Share the Post:

Related Posts