Skip to content

Fix unsanitized place_name rendering and bump version - #335

Merged
ibesora merged 3 commits into
mainfrom
ibesora/fix-place-name-vuln
Jul 16, 2026
Merged

ibesora merged 3 commits into
mainfrom
ibesora/fix-place-name-vuln

Conversation

@ibesora

@ibesora ibesora commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

This PR fixes a vulnerability that occurred when the geocoding results included an unsanitized place_name.
Results were being directly rendered without any escaping.

This PR also bumps the version to 4.3.3 so we can do another release.

@ibesora
ibesora requested a review from underoot July 15, 2026 16:30
underoot
underoot previously approved these changes Jul 15, 2026
@ibesora
ibesora merged commit fb04915 into main Jul 16, 2026
7 checks passed
@ibesora
ibesora deleted the ibesora/fix-place-name-vuln branch July 16, 2026 15:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants