Skip to content

fix: Escape custom attribution to avoid XSS #67#2535

Merged
hupf merged 1 commit intomainfrom
bug/maplayer-xss
Mar 12, 2026
Merged

fix: Escape custom attribution to avoid XSS #67#2535
hupf merged 1 commit intomainfrom
bug/maplayer-xss

Conversation

@hupf
Copy link
Contributor

@hupf hupf commented Mar 12, 2026

Closes #67

This PR fixes an XSS vulnerability because the custom attribution is rendered without escaping.


  • I added a CHANGELOG entry
  • I made a self-review of my own code
  • I wrote tests for the changes (if applicable)
  • I wrote configurator and chart config migrations (if applicable)

@hupf hupf self-assigned this Mar 12, 2026
@vercel
Copy link
Contributor

vercel bot commented Mar 12, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
visualization-tool Ready Ready Preview, Comment Mar 12, 2026 11:05am

Request Review

@hupf hupf merged commit abeb8b5 into main Mar 12, 2026
11 of 13 checks passed
@hupf hupf deleted the bug/maplayer-xss branch March 12, 2026 12:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants