XSS vulnerability in <ansi2html-1.9.4
ansi2html before 1.9.4 converted crafted sr.ht CI log lines into HTML, enabling XSS for viewers.
Sam James reported on oss-security that ansi2html versions before 1.9.4 can turn crafted lines in a build log into HTML. On SourceHut's sr.ht CI service, that behavior allowed cross-site scripting against people viewing the log. The report points to a write-up of an sr.ht account-takeover scenario; no CVE is named in the post.