Sourcehut account takeover via build logs (XSS in ansi2html)
What happened
A wormable vulnerability allowed anyone able to inject text in a build log on builds.sr.ht (or other instances) to take over accounts who viewed them
Summary assembled by rule from the sources below
Why it's spreading
Timeline
- First appeared on Hacker NewsHacker News
- Discussion started on LobstersLobsters