Drawing attention on this instance so Admins are aware and can address the propagating exploit.
EDIT: Found more info about the patch.
A more thorough recap of the issue.
GitHub PR fixing the bug: https://github.com/LemmyNet/lemmy-ui/pull/1897/files
If your instance has custom emojis defined, this is exploitable everywhere Markdown is available. It is NOT restricted to admins, but can be used to steal an adminβs JWT, which then lets the attacker get into that adminβs account which can then spread the exploit further by putting it somewhere where itβs rendered on every single page and then deface the site.
If your instance doesnβt have any custom emojis, you are safe, the exploit requires custom emojis to trigger the bad code branch.