Skip to content

Fix XSS vulnerability (CWE-79) via globally disabled HTML escaping in HAML - #443

Merged
robertcheramy merged 4 commits into
ytti:masterfrom
mattimustang:fix/xss-escape-html
Jul 31, 2026
Merged

Fix XSS vulnerability (CWE-79) via globally disabled HTML escaping in HAML#443
robertcheramy merged 4 commits into
ytti:masterfrom
mattimustang:fix/xss-escape-html

test: use attribute-breaking payload in stored XSS specs

301baed
Select commit
Loading
Failed to load commit list.
Sign in for the full log view