Skip to content

[core] Fix stored XSS in VBHTMLRenderer and YAHTMLRenderer#6475

Merged
adangel merged 1 commit intopmd:mainfrom
adangel:core/escape-vbhtml-yahtml
Feb 27, 2026
Merged

[core] Fix stored XSS in VBHTMLRenderer and YAHTMLRenderer#6475
adangel merged 1 commit intopmd:mainfrom
adangel:core/escape-vbhtml-yahtml

Conversation

@adangel
Copy link
Member

@adangel adangel commented Feb 27, 2026

Describe the PR

These renders don't always escape the output properly.

Related issues

Ready?

  • Added unit tests for fixed bug/feature
  • Passing all unit tests
  • Complete build ./mvnw clean verify passes (checked automatically by github actions)
  • Added (in-code) documentation (if needed)

@adangel adangel added this to the 7.22.0 milestone Feb 27, 2026
@pmd-actions-helper
Copy link
Contributor

Documentation Preview

Compared to main:
This changeset changes 0 violations,
introduces 0 new violations, 0 new errors and 0 new configuration errors,
removes 0 violations, 0 errors and 0 configuration errors.

Regression Tester Report

(comment created at 2026-02-27 09:44:40+00:00 for 96598aa)

@adangel adangel merged commit c140c0e into pmd:main Feb 27, 2026
13 checks passed
@adangel adangel deleted the core/escape-vbhtml-yahtml branch February 27, 2026 10:02
adangel added a commit that referenced this pull request Feb 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant