Sourcehut account takeover via build logs (XSS in ansi2html)

·Hacker News··

A wormable vulnerability allowed anyone able to inject text in a build log on builds.sr.ht (or other instances) to take over accounts who viewed them

Read full article →

Related Articles

Two-tier encryption in the UK
ReturnoftheHack · Hacker News · 10h ago
F-Droid 2.0
daveoc64 · Hacker News · 5h ago
Creatine uptake enhances antitumor immunity
lormayna · Hacker News · 2h ago
Italian parliament votes for return to nuclear energy
geox · Hacker News · 1d ago
Google’s Project Suncatcher to put ML infrastructure in space
xnx · Hacker News · 7h ago