‹ BackHN Continuity

Thread

Sourcehut account takeover via build logs (XSS in ansi2html)

153 points · 29 comments · arusekk

  1. nsagent · · focus · HN ↗
    &gt; So if you happen to be able to make ␛]8;;<a href="https:&#x2F;&#x2F;example.com&#x2F;&quot;&#x2F;...␇" rel="nofollow">https:&#x2F;&#x2F;example.com&#x2F;&quot;&#x2F;...␇ appear in the job logs —4 which you can, either without even having an account, by sending a patch to a public mailing list with continuous integration turned on

    The fact that this could be triggered so easily — just sending a malicious patch to a mailing list — is pretty insane.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.