MikeTrendsTrends right now

Mmastodon TechnologyTechnology first seen 20 h ago, last 20 h ago, peak #3

SourceHut account takeover flaw found in build log rendering

Original: SourceHut account takeover via build logs (XSS in ansi2html.py) | CVE-2026-92973 https:// reddthat.com/post/74210240

A security vulnerability in SourceHut, tracked as CVE-2026-92973, reportedly allowed account takeover through malicious build logs. The flaw involved cross-site scripting in the ansi2html.py script used to render logs, letting attackers inject code that could hijack sessions. Developers and security researchers are discussing the disclosure and how the issue was handled.

Why now: The public disclosure of a newly assigned CVE affecting SourceHut is drawing attention from developers who use the platform for CI and code hosting.

SourceHutansi2html.pyCVE-2026-92973

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/763800