• Sources: primary, discussion
  • Summary: The report describes an XSS in ansi2html rendering of builds.sr.ht job logs, tracked as CVE-2026-92973 and fixed in ansi2html 1.9.4 and builds.sr.ht 0.105.1. Getting text into a build log was enough to trigger it, including by mailing a patch to a public list with CI enabled and without holding an account. The build log page carries the CSRF token in the DOM and builds.sr.ht holds deploy keys for sr.ht itself, and the author reasons from those two facts that a payload could reach both, while stating he did not build or run one. He states the flaw sat in builds.sr.ht for about four and a half years.
  • Why it matters: Build log output is attacker-controlled text on any CI system that accepts outside patches, and rendering it as markup let a public mailing list post execute script in the browser of everyone who read the job.

send feedback on this story