| |
A security researcher discovered a cross-site scripting (XSS) vulnerability in SourceHut's build logs through the ansi2html library, which converts ANSI escape codes to HTML. The vulnerability could potentially allow account takeover by injecting malicious code through build log output. The researcher found the issue while investigating inefficient CSS generation in build logs and reported it to the unmaintained ansi2html repository.
Read Full Article →
← More Tech news