From b858e8d1085ef01faaf77162a6a2973e17a47aaa Mon Sep 17 00:00:00 2001 From: Leo Date: Mon, 20 Apr 2026 22:51:47 +0800 Subject: fix: HTML-escape crawled document metadata in ViewFile parsed view to prevent XSS (#630) dc_title, dc_creator, dc_subject, dc_description, dc_publisher, dc_format, and dc_identifier were all written with prop.put() and rendered unescaped in HTML
elements. A malicious page title like