Get the latest tech news

Sourcehut account takeover via build logs (XSS in ansi2html)


A wormable vulnerability allowed anyone able to inject text in a build log on builds.sr.ht (or other instances) to take over accounts who viewed them

None

Get the Android app

Or read this on Hacker News

Read more on:

Photo of takeover

takeover

Photo of XSS

XSS

Photo of SourceHut

SourceHut

Related news:

News photo

Blizzard confirms Diablo 5 won't gloss over Diablo's takeover of Sanctuary — 'It's not going to take place entirely off-screen'

News photo

DOGE Staffers Are Back—and Leading AI Takeover of Government Services

News photo

Diablo 5 senior game director says the game will tell 'three stories,' including the past, the present desolation of Diablo's takeover, and the future 'terror forming' of Sanctuary