fix(ui): escape HTML in codespan renderer to prevent tag injection

The custom codespan renderer injected raw text into <code> tags without
HTML-escaping. When backtick-wrapped content contained HTML tags like
`<textarea>`, the raw tag entered the DOM. Since <textarea> is a raw
text element in HTML, the browser's parser consumed all subsequent
content as textarea text, breaking <code> tag pairing and leaving
</code> visible as literal text.
This commit is contained in:
Mark IJbema
2026-03-23 13:18:45 +01:00
parent 63a9e9f6e9
commit 18824710c7
+8 -2
View File
@@ -632,12 +632,18 @@ export const { use: useMarked, provider: MarkedProvider } = createSimpleContext(
// kilocode_change start
codespan({ text }) {
const file = parseFilePath(text)
const escaped = text
.replace(/&/g, "&amp;")
.replace(/</g, "&lt;")
.replace(/>/g, "&gt;")
.replace(/"/g, "&quot;")
.replace(/'/g, "&#39;")
if (file) {
const lineAttr = file.line ? ` data-file-line="${file.line}"` : ""
const colAttr = file.column ? ` data-file-col="${file.column}"` : ""
return `<code class="file-link" data-file-path="${file.path}"${lineAttr}${colAttr}>${text}</code>`
return `<code class="file-link" data-file-path="${file.path}"${lineAttr}${colAttr}>${escaped}</code>`
}
return `<code>${text}</code>`
return `<code>${escaped}</code>`
},
code({ text, lang }) {
const escaped = text