mirror of
https://github.com/discourse/discourse.git
synced 2025-02-15 15:55:09 +00:00
Non-markdown tags weren't being escaped in chat excerpts. This could be triggered by editing a chat message containing a tag (self XSS), or by replying to a chat message with a tag (XSS). Co-authored-by: Jan Cernik <jancernik12@gmail.com>