Skip to content

template: escape untrusted names in locale strings piped through Safe#8176

Merged
unknwon merged 3 commits intomainfrom
GHSA-vgvf-m4fw-938j
Feb 13, 2026
Merged

template: escape untrusted names in locale strings piped through Safe#8176
unknwon merged 3 commits intomainfrom
GHSA-vgvf-m4fw-938j

Conversation

@unknwon
Copy link
Member

@unknwon unknwon commented Feb 13, 2026

Summary

  • Add HTMLEscape template function (template.HTMLEscapeString).
  • Escape git committer/author names before interpolating them into locale strings that are piped through Safe, in branch overview, branch list, and wiki view templates.

Ref: GHSA-vgvf-m4fw-938j

🤖 Generated with Claude Code

unknwon and others added 3 commits February 12, 2026 21:27
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@unknwon unknwon merged commit ac21150 into main Feb 13, 2026
6 checks passed
@unknwon unknwon deleted the GHSA-vgvf-m4fw-938j branch February 13, 2026 02:42
@unknwon unknwon added this to the 0.14.2 milestone Feb 13, 2026
unknwon added a commit that referenced this pull request Feb 19, 2026
…#8176)

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant