From 18824710c79c6cdc1f71d3dc89dfd9be9100f911 Mon Sep 17 00:00:00 2001 From: Mark IJbema Date: Mon, 23 Mar 2026 13:18:45 +0100 Subject: [PATCH] fix(ui): escape HTML in codespan renderer to prevent tag injection The custom codespan renderer injected raw text into tags without HTML-escaping. When backtick-wrapped content contained HTML tags like `