Cybersecurity

Sourcehut account takeover via build logs (XSS in ansi2html)

Sourcehut, a platform for open-source projects, has been vulnerable to account takeover due to an XSS vulnerability in its ansi2html feature. The issue was discovered and reported by a security researcher. The vulnerability allowed attackers to steal user credentials and take over accounts. The issue has been patched, and users are advised to update their accounts. Sourcehut has also been in touch with affected users to assist with the issue.

Read the full article at blog.arusekk.pl →