Post

SourceHut account takeover via build logs (XSS in ansi2html.py)

A crafted ANSI OSC 8 hyperlink in a CI log could run JavaScript in a viewer’s browser and expose SourceHut credentials or deploy keys. The researcher says the flaw affected ansi2html before 1.9.4 and builds.sr.ht before 0.105.1; SourceHut mitigated it in August, and the upstream library fix shipped September 2, 2026.

The HN discussion focused on the CI threat boundary: an attacker could get malicious output into logs through a public mailing-list patch, and one commenter highlighted that SourceHut’s own deploy keys were present in its build service. Others noted the difficulty of safely rendering untrusted build output and debated the usability cost of stripping OSC 8 hyperlinks. This is a disclosure write-up of a patched issue, not evidence of ongoing exploitation.