EDIT: not popped, just someone publishing a URL with this vuln in mastodon tripped OVH’s detection: https://github.com/mastodon/mastodon/security/advisories/GHSA-xqw8-4j56-5hj6
Hm, cathode church got popped. Sorry everyone. Will work on recovery tonight.