# SourceHut patches build-log flaw that could run attacker code in viewers' browsers

_Published Thursday, September 24, 2026 at 11:21 PM EDT · Security · Latest · Tier 2 — Notable_

A security researcher disclosed a flaw in SourceHut's build-log display that could let an attacker place browser-executed code in a job log. The researcher said crafted hyperlink control sequences passed through the ansi2html converter could become unsafe links or page elements when someone viewed the log.

The researcher said an attacker could get malicious text into a log through a patch sent to a public mailing list with continuous integration enabled. Code running in a viewer's browser could then act with that viewer's SourceHut access, potentially exposing build credentials. SourceHut patched its build service to sanitize the converted output; the account does not establish that attackers used the flaw.

## Sources

- [blog.arusekk.pl](https://blog.arusekk.pl/posts/srht-account-takeover/)

---
Canonical: https://techandbusiness.org/newswire/N3wR4G2W_n-eMbJ1NV1JXa
Published: 2026-09-25T03:21:12.475Z
Story chronology: 2026-09-23T00:00:00.000Z
Retrieved: 2026-09-25T04:49:02.615Z
Publisher: Tech & Business (techandbusiness.org)
