Skip to content

SourceHut account takeover via build logs (XSS in ansi2html.py)

8.2 relevance
Score Breakdown
technical depth
9
novelty
8
actionability
9
community
7
strategic
6
personal
8

Scored daily by a customisable AI persona to surface the most relevant engineering leadership news.

Detailed security vulnerability with immediate actionable steps for users.

General blog.arusekk.pl
Summary

A researcher discovered an XSS vulnerability in SourceHut's builds.sr.ht microservice, where the ansi2html.py script improperly sanitizes OSC 8 hyperlinks, allowing injection of arbitrary HTML attributes (e.g., onfocus) to execute JavaScript and achieve account takeover. The code had been unmaintained for over a year before a fix was submitted.

Author

Arusekk