Post #23399 75 Sep 24, 2026, 18:10 UTC SourceHut account takeover via build logshttps://blog.arusekk.pl/posts/srht-account-takeover/@secharvester Arusekk blog SourceHut account takeover via build logs (XSS in ansi2html.py) | CVE-2026-92973 A wormable vulnerability allowed anyone able to inject text in a build log on builds.sr.ht (or other instances) to take over accounts who viewed them