Elektrine lite

← Feed

@Arusekk@infosec.exchange

2026-09-24 09:31 UTC

For 4,5 years anyone could add rogue JavaScript to build log page by submitting a builds.sr.ht job with OSC 8 escape codes. The attacker could submit build jobs on behalf of the victim viewing the build logs, up to even deploying rogue software on the flagship instance. Curious? Read about the whole journey here: https://blog.arusekk.pl/posts/srht-account-takeover/ #cve_2026_92973 #srht #sourcehut #xss #security #osc8 #ansiescape #ci #vulnerability

Replies (0)

No replies.