Skip to content

Commit 01acf79

Browse files
committed
Fix for potential XSS attacks.
1 parent f45966d commit 01acf79

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

extractor/src/main/java/org/schabi/newpipe/extractor/services/youtube/YoutubeParsingHelper.java

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@
3333
import com.grack.nanojson.JsonParser;
3434
import com.grack.nanojson.JsonParserException;
3535
import com.grack.nanojson.JsonWriter;
36-
36+
import org.jsoup.nodes.Entities;
3737
import org.schabi.newpipe.extractor.MetaInfo;
3838
import org.schabi.newpipe.extractor.downloader.Response;
3939
import org.schabi.newpipe.extractor.exceptions.AccountTerminatedException;
@@ -967,7 +967,7 @@ public static String getTextFromObject(final JsonObject textObject, final boolea
967967
textBuilder.append("<s>");
968968
}
969969

970-
textBuilder.append(text);
970+
textBuilder.append(Entities.escape(text));
971971

972972
if (strikethrough) {
973973
textBuilder.append("</s>");

0 commit comments

Comments
 (0)