A cross-site scripting (XSS) vulnerability in the ansi2html library exposed Sourcehut users to account takeover attacks through malicious build log output. The flaw allowed attackers to inject arbitrary code into rendered logs.
Security researcher Artur Seketkski disclosed a critical XSS vulnerability in Sourcehut's handling of build logs. The bug existed in how the platform processed ANSI escape sequences using the ansi2html library.
Attackers could craft malicious build output containing specially formatted sequences that, when rendered by the web interface, executed arbitrary JavaScript in users' browsers. This enabled session hijacking and full account compromise.
The vulnerability affected any Sourcehut user viewing build logs from untrusted sources—a common scenario in CI/CD pipelines. An attacker with the ability to inject content into build output could target project maintainers and other developers.
Sourcehut has patched the vulnerability. Users should update their instances immediately. The incident highlights risks in sanitizing user-generated content in build systems, where output formatting libraries may introduce security gaps.
The disclosure received significant attention on Hacker News, with 104 points and 20 comments discussing the implications for other platforms using similar log rendering approaches.
Two developers independently demonstrated that Meta's Muse AI can be prompted to download and share its entire filesystem, including system files and internal documentation. The vulnerability reportedly requires minimal effort to exploit.
Arista Networks has released security patches for a zero-day vulnerability in VeloCloud Orchestrator (VCO) On-Prem that is currently being exploited in the wild.
A new MacSync malware variant targeting macOS systems exploits public iCloud calendar events to deliver updated native payloads. The technique represents a shift in the malware's distribution strategy.
A new botnet called Carbonato is exploiting exposed Docker daemons to install the Hermes Agent AI framework and commandeer infected systems. The malware targets insecure Docker configurations to establish control over hosts.