SourceHut account takeover via build logs (XSS in ansi2html.py)
Lobsters·95 points·winter·6 days ago·blog.arusekk.pl
A wormable vulnerability allowed anyone able to inject text in a build log on builds.sr.ht (or other instances) to take over accounts who viewed them
Read the full article at blog.arusekk.pl →
Related stories
- Sourcehut account takeover via build logs (XSS in ansi2html)blog.arusekk.plHacker News · 134 points · 6 days ago
- Hacker News · 3 points · 6 days ago
- Understand any Bluesky account (Jev)jev.0x0.booHacker News · 3 points · 11 days ago
- Show HN: Deterministic UI testing that checks backend logs, not just the UIget-verirun.duely.inHacker News · 1 points · 10 days ago
- Hacker News · 1 points · 10 days ago
- Hacker News · 2 points · 11 days ago