SourceHut build logs hid a wormable XSS that could take over accounts

A vulnerability researcher known as Arusekk published a writeup on September 23 describing CVE-2026-92973, a cross-site scripting flaw in the ansi2html library that let anyone who could inject text into a SourceHut build log take over the accounts of people who viewed it. The bug had been sitting in the wild for close to four […]