Browse Source

[fix] route /autocompleter: escape '<' and '>' in the response

Signed-off-by: Markus Heiser <markus.heiser@darmarit.de>
Markus Heiser 3 years ago
parent
commit
9a3253fc16
1 changed files with 1 additions and 0 deletions
  1. 1 0
      searx/webapp.py

+ 1 - 0
searx/webapp.py

@@ -916,6 +916,7 @@ def autocompleter():
         suggestions = json.dumps([sug_prefix, results])
         suggestions = json.dumps([sug_prefix, results])
         mimetype = 'application/x-suggestions+json'
         mimetype = 'application/x-suggestions+json'
 
 
+    suggestions = escape(suggestions, False)
     return Response(suggestions, mimetype=mimetype)
     return Response(suggestions, mimetype=mimetype)