@p pleroma decided to have a bug that allows javascript code to be executed if you upload a javascript script. Since the script is @ root domain its just automatically executed apparently. We don't have a media proxy so remote users can't really do anything but local users can :D