mirror of
https://github.com/streamyfin/streamyfin.git
synced 2026-06-02 12:08:37 +01:00
Security audit: the bot echoes other issues' titles back into a comment, so a maliciously-named issue could ping (@everyone) or inject markdown/HTML. Break @-mentions with a zero-width space and strip markdown/HTML control chars before posting.