For 4,5 years anyone could add rogue JavaScript to build log page by submitting a builds.sr.ht job with OSC 8 escape codes. The attacker could submit build jobs on behalf of the victim viewing the build logs, up to even deploying rogue software on the flagship instance. Curious? Read about the whole journey here:
https://blog.arusekk.pl/posts/srht-account-takeover/
#cve_2026_92973 #srht #sourcehut #xss #security #osc8 #ansiescape #ci #vulnerability
#ansiescape
2 posts · Last used 14d
ANSI escape injection in MCP servers: Hidden from humans, visible to AI
https://brightsec.com/research/detecting-ansi-escape-sequence-injection-in-mcp-servers-with-dast/
Comments: https://news.ycombinator.com/item?id=48989006
#HackerNews #ANSIescape #MCPservers #cybersecurity #AIdetection #vulnerability
You've seen all posts
