DigiNews

Tech Watch by Johan Denoyer

← Back to articles

SourceHut account takeover via build logs (XSS in ansi2html.py) | CVE-2026-92973

Quality: 8/10 Relevance: 9/10

Summary

The post details a wormable vulnerability in ansi2html (CVE-2026-92973) that enables account takeover via injection in build logs on builds.sr.ht. It describes the vulnerability’s technical vectors, potential impact on deploy keys and admin access, timelines, and mitigations, and discusses coordination with upstream and CVE submission. It also provides indicators of compromise and defense-in-depth recommendations.

🚀 Service construit par Johan Denoyer