Screenshot
If you own a TweetDeck account, we recommend you log out of TweetDeck but also revoke its access to Twitter until the company fixes this security issue.
According to programmer Chris Williams, Tweetdeck "is not stripping out dangerous scripting code from tweets," which in turn allows anyone to "run Javascript in the context of another user."
@astroehlein at the moment, people are just opening alert boxes. Next, there'll be tweets trying to steal login tokens etc
- Chris Williams (@diodesign) June 11, 2014
The vulnerability currently affects Tweetdeck's browser plug-in for Google Chrome. It apparently doesn't affect the desktop app for Mac or Windows, but you're safer changing your password just in case.
We've reached out to Twitter and we'll update this story as soon as we learn more.