Sourcehut account takeover via build logs (XSS in ansi2html)

A flaw in SourceHut’s build log rendering (ansi2html) allowed malicious ANSI/OSC sequences to become executable HTML/JavaScript, turning a routine log view into a path for account takeover and potentially broader platform compromise. For CIOs and technology leaders, the business risk is that CI/CD and developer tooling can become an attack surface for identity theft, unauthorized code access, and exposure of sensitive deploy keys; this underscores the need to treat log viewers and text-to-HTML converters as security-critical components in the software supply chain.

Hacker News3 min read
Read full article
Sourcehut account takeover via build logs (XSS in ansi2html)

Read the full story at Hacker News →