A report published on September 24, 2026 describes how crafted build-log lines could be converted to HTML and enable XSS for viewers using ansi2html before version 1.9.4.
A report shared on the oss-sec feed on September 24, 2026 describes a cross-site scripting (XSS) vulnerability in ansi2html versions before 1.9.4. The feed's published translation is automatic.
According to the report, specially crafted build-log lines could be converted into HTML and trigger XSS in the browser of anyone viewing the log. The case mentioned involves build logs in the sr.ht continuous-integration service; the text also points to a technical write-up about the incident.
To assess exposure, check whether your organization uses ansi2html to render logs and verify the installed version. Consult the original oss-sec post and its cited technical write-up to check details, context, and any remediation guidance; do not assume the short description includes every step or impact.
If you use AI to study or apply this material, remove personal data and secrets from logs before submitting any excerpts. Compare conclusions with the original sources and follow your organization's security update and validation process.