Part of a story covered by 3 sources: “Stored XSS in ansi2html before 1.9.4 via SourceHut CI build logs enables account takeover” — merged summary and timeline →
Re: XSS vulnerability in <ansi2html-1.9.4
AI summary · grok-4.7
An oss-security reply points to a Hacker News thread on XSS in ansi2html 1.9.4.
Sebastian Pipping posted a brief oss-security follow-up about an XSS vulnerability in ansi2html before version 1.9.4. The message gives no technical details, CVE, or patch information and only links a related Hacker News thread. Nothing in the post says the flaw is being exploited.
- Post is only a pointer to a Hacker News thread.
- Title cites XSS in ansi2html before 1.9.4.
- No CVE, exploit details, or patch are included.
Productsansi2html
Full article
Posted by Sebastian Pipping on Sep 25 For anyone interested, the related thread on Hacker News is this: https://news.ycombinator.com/item?id=49835996
This source does not provide full text. Read it at seclists.org.