Hacker News
Sourcehut account takeover via build logs (XSS in ansi2html)
A security researcher discovered a cross-site scripting (XSS) vulnerability in the `ansi2html` library used by SourceHut. By crafting malicious ANSI escape sequences, an attacker can inject arbitrary JavaScript into build logs. This flaw allows for potential account takeovers by executing malicious code within the browser sessions of users viewing the logs.