SourceHut Account Takeover via Build Logs: XSS in ansi2html

Sourcehut account takeover via build logs (XSS in ansi2html)

A researcher discovered a cross-site scripting flaw in ansi2html, the library SourceHut uses to render build logs. By injecting a crafted ANSI escape sequence into a log, an attacker could execute JavaScript in the browser of anyone viewing the log, including admins. The vulnerability, tracked as CVE-2026-92973, allowed account takeover and access to deploy keys. SourceHut patched builds.sr.ht to sanitize output, and upstream ansi2html released fixes.

Once you get an admin to view it, you can probably grant yourself admin rights. The worse impact is that you have access to all the deploy keys, and on builds.sr.ht, there are deploy keys for sr.ht itself.
  1. kwhitlock

    Build logs are such a tricky attack surface; sanitizing arbitrary build output is practically impossible without breaking useful formatting. Always assume untrusted input.

  2. Joker_vD

    Oh my God, it's OSC 8 again. Because copy-pasting an URI from the terminal window is so 2003, and goodness gracious, having to look at an actual URL instead of an arbitrarily inaccurate description of it? That's, like, 1993. When I wrote my variant of ansi2html, I aggressively stripped out every C0 and C1, and all of the possible APC/DCS/OSC/PM sequences.

    Meanwhile, internal links between different parts of a man page still don't exist (unless you use GNU Info but seriously, I'd rather use lynx on a folder of HTML files instead).

  3. bstsb

    haven’t been properly rickrolled in years, wasn’t expecting that!

More from this day

2026-09-24