From d2ff9d2617d099fff64e999233e9fb3fbf70b9f6 Mon Sep 17 00:00:00 2001 From: ergosteur Date: Fri, 21 Aug 2026 17:13:23 -0400 Subject: [PATCH] Fix stored-HTML-injection: escape AD data before it hits Markdown tables Every table cell fed from directory content (descriptions, sAMAccountName, OS strings, DNs, object classes) was interpolated into the Markdown report raw. python-markdown doesn't escape inline HTML by default, so a directory-controlled value like an OU description containing