Skip to content

Commit eda91c8

Browse files
committed
escape
1 parent 6bf3895 commit eda91c8

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

packages/kit/src/core/sync/write_server.js

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@ import { load_error_page, load_template } from '../config/index.js';
77
import { runtime_directory } from '../utils.js';
88
import { isSvelte5Plus, write_if_changed } from './utils.js';
99
import colors from 'kleur';
10+
import { escape_html } from '../../utils/escape.js';
1011

1112
/**
1213
* @param {{
@@ -54,7 +55,7 @@ export const options = {
5455
.replace('%sveltekit.body%', '" + body + "')
5556
.replace(/%sveltekit\.assets%/g, '" + assets + "')
5657
.replace(/%sveltekit\.nonce%/g, '" + nonce + "')
57-
.replace(/%sveltekit\.version%/g, config.kit.version.name)
58+
.replace(/%sveltekit\.version%/g, escape_html(config.kit.version.name))
5859
.replace(
5960
/%sveltekit\.env\.([^%]+)%/g,
6061
(_match, capture) => `" + (env[${s(capture)}] ?? "") + "`

0 commit comments

Comments
 (0)