Skip to content

Conversation

@jeremystretch
Copy link
Member

Fixes: #18379

Remove the safe filter from RSS feed content. This will likely break some corner cases where special character rendering fails.

@jeremystretch jeremystretch merged commit a9f3c74 into main Jan 17, 2025
6 checks passed
@jeremystretch jeremystretch deleted the 18379-rss-content-sanitization branch January 17, 2025 15:25
@ITEAmplify
Copy link

Hey, after this change it seems that rss feed is not getting formatted anymore and shows html as plain text

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Feb 20, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

XSS in RSS Feed Summary Tag can lead to RCE or SuperUser Creation - CVE-2024-56915

4 participants