Sourcehut account takeover via build logs (XSS in ansi2html)
Arusekk blog
Sourcehut account takeover via build logs (XSS in ansi2html)
A wormable vulnerability allowed anyone able to inject text in a build log on builds.sr.ht (or other instances) to take over accounts who viewed them
0 comments
No comments yet.