Skip to content

htmlreport: escape message and file name in generated pages - #8920

Open
Nussu06 wants to merge 1 commit into
cppcheck-opensource:mainfrom
Nussu06:htmlreport-escape-msg-filename
Open

Nussu06 wants to merge 1 commit into
cppcheck-opensource:mainfrom
Nussu06:htmlreport-escape-msg-filename

Conversation

@Nussu06

@Nussu06 Nussu06 commented Oct 5, 2026

Copy link
Copy Markdown

AnnotateCodeFormatter.wrap put the error message into the annotated source page, and main put the file name into the index, stats and per-file pages, without html_escape, so text from the checked code such as #error <img src=x onerror=alert(1)> or a file named <b>x.c became live markup in the report; both now go through html_escape like the verbose text and the index message already do, and test_htmlreport.py has a test for it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant