Skip to content

Commit cafec25

Browse files
committed
escape HTML chars
1 parent 9b80f6e commit cafec25

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

addon-api/content-script/blocks.js

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -152,7 +152,7 @@ const generateBlockXML = () => {
152152
` argumentdefaults="${escapeHTML(JSON.stringify(defaults))}"` +
153153
"></mutation></block>";
154154
} else {
155-
xml += `<block type="${blockData.type}"><field name="VALUE">${blockData.id}</field></block>`;
155+
xml += `<block type="${escapeHTML(blockData.type)}"><field name="VALUE">${escapeHTML(blockData.id)}</field></block>`;
156156
}
157157
}
158158
if (xml.length === 0) {

0 commit comments

Comments
 (0)