CVE-2025-53941: Fedify-Dev Hollo
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Versions prior to 0.6.5 allow HTML form elements to be submitted, making the software vulnerable to HTML injection. Version 0.6.5 fixes the issue.
Affected products
- Fedify-Dev Hollo: before 0.6.5 (fixed in 0.6.5)
Published 2025-07-17. Last modified 2026-06-17.