E-Ink News Daily

← Back to list

SourceHut account takeover via build logs (XSS in ansi2html.py)

A critical XSS vulnerability (CVE-2026-92973) in ansi2html.py within SourceHut's CI build logs allows account takeover. The vulnerability was discovered by researcher Arusekk while setting up a personal SourceHut instance, where malicious payload injection via build logs could execute in other users' sessions.

Background

SourceHut (sr.ht) is a full-stack open source platform offering git hosting, CI/CD, issue tracking, and more. The ansi2html.py library is used to convert ANSI-colored terminal output into HTML for display in build logs.

Source
Lobsters
Published
Sep 25, 2026 at 04:38 AM
Score
7.0 / 10