SourceHut account takeover via build logs (XSS in ansi2html.py) | CVE-2026-92973 | Arusekk blog
Turns out the ANSI escape sequence set has been extended with OSC 8, hyperlinks, and ansi2html.py had an over-permissive parser which allowed XSS. hooray, a whole new attack vector to worry about!
Tags: ansi escape-sequences osc-8 hyperlinks xss links logs exploits infosec