A critical XSS vulnerability (CVE-2026-92973) in ansi2html.py within SourceHut's CI build logs allows account takeover. The vulnerability was discovered by researcher Arusekk while setting up a personal SourceHut instance, where malicious payload injection via build logs could execute in other users' sessions.
Background
SourceHut (sr.ht) is a full-stack open source platform offering git hosting, CI/CD, issue tracking, and more. The ansi2html.py library is used to convert ANSI-colored terminal output into HTML for display in build logs.
- Source
- Lobsters
- Published
- Sep 25, 2026 at 04:38 AM
- Score
- 7.0 / 10