← Back to events
ActiveTechAcquisition

Sourcehut account takeover via build logs (XSS in ansi2html)

What happened

A wormable vulnerability allowed anyone able to inject text in a build log on builds.sr.ht (or other instances) to take over accounts who viewed them

Summary assembled by rule from the sources below

Why it's spreading

Timeline

  1. First appeared on Hacker NewsHacker News
  2. Discussion started on LobstersLobsters

Sources