diff --git a/pagure/ui/filters.py b/pagure/ui/filters.py index 6c03e52..b8cab5f 100644 --- a/pagure/ui/filters.py +++ b/pagure/ui/filters.py @@ -11,8 +11,9 @@ import datetime import textwrap -import flask import arrow +import bleach +import flask import markdown from pygments import highlight @@ -305,9 +306,7 @@ def no_js(content): """ Template filter replacing ', '</script>') - return content + return bleach.clean(content) @APP.template_filter('toRGB')