From 9bd21a6e204eef8f58337640112535cddc95ce74 Mon Sep 17 00:00:00 2001 From: Christian Chwala Date: Wed, 29 Apr 2026 22:49:46 +0200 Subject: [PATCH] fix: stored XSS in generate_cml_map (hotfix 2) - Use json.dumps() for cml_ids_json instead of str/replace to prevent JSON injection in the inline