importantSYS.SOURCE: Arusekk blog• 2026-09-24T19:54:21Z
XSS Vulnerability in SourceHut's ansi2html.py Enables Account Takeover
A critical XSS vulnerability in SourceHut's ansi2html.py allowed attackers to execute arbitrary scripts via malicious build logs, enabling account takeovers. The issue was mitigated through output sanitization and highlighted the need for stricter Content-Security-Policy implementations.
*** END OF TRANSMISSION ***