{
  "id": 9629528,
  "title": "SourceHut account takeover via build logs (XSS in ansi2html.py)",
  "url": "https://urgent.news/2026/09/24/sourcehut-account-takeover-via-build-logs-xss-in-ansi2html-py",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-24T20:38:32.000Z",
  "source": {
    "name": "Lobsters",
    "slug": "lobsters",
    "url": "https://blog.arusekk.pl/posts/srht-account-takeover/"
  },
  "original_language": "en",
  "account": "SourceHut account takeover via build logs (XSS in ansi2html.py) occurred due to a vulnerability in the ansi2html.py script. This script converts ANSI escape codes to HTML, allowing for automatic links and OSC 8 hyperlinks. An attacker could craft a malicious input string to inject an XSS payload into the job logs. This payload could be downloaded from an attacker's website and executed in any browser that views the job log. The attacker could subsequently gain access to deploy keys and admin rights on the SourceHut platform. Defense against this vulnerability should involve restricting Content-Security-Policy and improving sanitization in the ansi2html.py script.",
  "summary": null,
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}