From fa1fe7f866a73fc8d31b78e67faa7cd76dfbeb63 Mon Sep 17 00:00:00 2001
From: Joeseph Grey <212606152+StressTestor@users.noreply.github.com>
Date: Thu, 4 Jun 2026 06:42:49 -0600
Subject: [PATCH] security: sanitize rendered research-report HTML (#364)
The visual research report is assembled from LLM output over crawled web
pages (untrusted content) and served under a relaxed `script-src
'unsafe-inline'` CSP. Two values reached that HTML without sanitization:
- `_md_to_html` rendered the report markdown via python-markdown, which
passes raw HTML through verbatim, so `",
+ '',
+ "