There is a cross-site scripting vulnerability in the development (1.0.x) branch of StatusNet, including the alpha4 release previously available for download from the StatusNet site.
The vulnerability is due to insufficient sanitization of user input of the description field in the question-and-answer (QnA) plugin. Attackers could post hostile Javascript or other HTML code into the application that would be seen, and executed, by other users on the network. Versions of the 1.0.x branch below alpha5 are affected.