
I would be very surprised if the lemmy server would sanitize comment bodies, as they are just supposed to be markdown input. That’s the responsibility of the frontend, like lemmy-ui. Depending on the markdown library used, it could either just remove any HTML elements or escape them.
I guess we could try it out right here:
<script>alert(“XSS”)</script>









looks like it’s the latter for lemmy-ui. (And the former for mlmym, which is my default frontend.)