From bd8c13067d7a87083a82ee972fd677e9d16e7297 Mon Sep 17 00:00:00 2001 From: RumovZ Date: Tue, 25 May 2021 19:28:51 +0200 Subject: [PATCH] Escape HTML in template error message --- rslib/src/template.rs | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rslib/src/template.rs b/rslib/src/template.rs index 338558139..d2618d8bb 100644 --- a/rslib/src/template.rs +++ b/rslib/src/template.rs @@ -260,7 +260,7 @@ fn template_error_to_anki_error(err: TemplateError, q_side: bool, tr: &I18n) -> } else { tr.card_template_rendering_back_side_problem() }; - let details = localized_template_error(tr, err); + let details = htmlescape::encode_minimal(&localized_template_error(tr, err)); let more_info = tr.card_template_rendering_more_info(); let info = format!( "{}
{}
{}",