Skip to content

Commit 991394b

Browse files
authored
Merge pull request #1005 from FireMasterK/fix-escaping-xss
Fix for potential XSS attacks and formatting issues
2 parents ce15f7c + 01acf79 commit 991394b

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

extractor/src/main/java/org/schabi/newpipe/extractor/services/youtube/YoutubeParsingHelper.java

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@
3333
import com.grack.nanojson.JsonParser;
3434
import com.grack.nanojson.JsonParserException;
3535
import com.grack.nanojson.JsonWriter;
36-
36+
import org.jsoup.nodes.Entities;
3737
import org.schabi.newpipe.extractor.MetaInfo;
3838
import org.schabi.newpipe.extractor.downloader.Response;
3939
import org.schabi.newpipe.extractor.exceptions.AccountTerminatedException;
@@ -967,7 +967,7 @@ public static String getTextFromObject(final JsonObject textObject, final boolea
967967
textBuilder.append("<s>");
968968
}
969969

970-
textBuilder.append(text);
970+
textBuilder.append(Entities.escape(text));
971971

972972
if (strikethrough) {
973973
textBuilder.append("</s>");

0 commit comments

Comments
 (0)