SourceHut account takeover via build logs (XSS in ansi2html.py)
8.2 relevance
Score Breakdown
technical depth 9
novelty 8
actionability 9
community 7
strategic 6
personal 8
Scored daily by a customisable AI persona to surface the most relevant engineering leadership news.
Detailed security vulnerability with immediate actionable steps for users.
Summary
A researcher discovered an XSS vulnerability in SourceHut's builds.sr.ht microservice, where the ansi2html.py script improperly sanitizes OSC 8 hyperlinks, allowing injection of arbitrary HTML attributes (e.g., onfocus) to execute JavaScript and achieve account takeover. The code had been unmaintained for over a year before a fix was submitted.
Author
Arusekk