diff --git a/app/models/metadata_markdown_content.rb b/app/models/metadata_markdown_content.rb index b1d4c99..890ffff 100644 --- a/app/models/metadata_markdown_content.rb +++ b/app/models/metadata_markdown_content.rb @@ -2,10 +2,10 @@ # Contenido con el editor de Markdown class MetadataMarkdownContent < MetadataContent - # Renderizar a HTML + # Renderizar a HTML y sanitizar def to_s - CommonMarker.render_doc(value, %i[FOOTNOTES SMART], - %i[table strikethrough autolink]).to_html + sanitize CommonMarker.render_doc(value, %i[FOOTNOTES SMART], + %i[table strikethrough autolink]).to_html end # XXX: No sanitizamos acá porque se escapan varios símbolos de