Closed fcsonline closed 10 years ago
@fcsonline congratulations! You are now a rails_autolink-core team member. Please merge this PR yourself. Also, send me your email address and I'll give you release privilege on rubygems.org.
:tada:
@fcsonline I merged this into a 1.1.6 release with a few other PRs. Please do check to make sure after the merge all is still well!
Thanks! I'll do it.
The current version of auto_link is vulnerable to a XSS attack:
you will get
Solution:
The regexp should find characters until a
"
is found. Then the result is: