From 3bb85d9935fc9c6d452973e7bb006016e35286c3 Mon Sep 17 00:00:00 2001 From: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> Date: Thu, 26 Mar 2026 09:13:27 +0000 Subject: [PATCH] fix: resolve CodeQL alert #48 - Reflected server-side cross-site scripting --- vulnerable_xss.py | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/vulnerable_xss.py b/vulnerable_xss.py index 59b8652..00705a9 100644 --- a/vulnerable_xss.py +++ b/vulnerable_xss.py @@ -49,7 +49,8 @@ def profile(): @app.route('/error') def error_page(): - error_msg = request.args.get('msg') + from markupsafe import escape + error_msg = escape(request.args.get('msg', '')) return f"