SourceHut account takeover via build logs (XSS in ansi2html.py)

Lobsters·95 points·winter·6 days ago·blog.arusekk.pl

A wormable vulnerability allowed anyone able to inject text in a build log on builds.sr.ht (or other instances) to take over accounts who viewed them

Read the full article at blog.arusekk.pl →

Related stories

Related topics