From 434be67a7d68bf29f323ef8ba715831122888c4c Mon Sep 17 00:00:00 2001 From: elhoim Date: Sun, 30 Aug 2026 23:43:49 +0000 Subject: [PATCH] Escape HTML in markdown report to prevent injection response_to_table and the summary/heading fields embedded attacker-influenced module output (WHOIS, passive DNS, sandbox responses) into the generated markdown report with only newline/pipe sanitization. Since the report is often rendered as HTML (e.g. via a markdown viewer), a module response containing