:
[SECURITY]■ STORY TIMELINE

SOURCEHUT VULNERABILITY ALLOWS ACCOUNT TAKEOVER VIA BUILD LOGS

A cross-site scripting (XSS) vulnerability in the ansi2html library exposed Sourcehut users to account takeover attacks through malicious build log output. The flaw allowed attackers to inject arbitrary code into rendered logs.

1 SOURCEFIRST SEEN SEP 24, 07:54 PM► READ THE ARTICLE
Hacker News+0m

Article URL: https://blog.arusekk.pl/posts/srht-account-takeover/ Comments URL: https://news.ycombinator.com/item?id=498…