A attacker can send the victim a message and if the victim tries to reply to it the attacker's javascript can run automatically apon opening message composer. This allows for an attacker to easily grab cookie and auto reply to their message on behalf of victim with victim's cookie, allowing session hijacking.
I'd say this deserves Highest priority since it's more common for people to message, especially after the friend request fix
@HullBreach this should get fixed ASAP