From 5a53ddb88c1b8ad5fbe9f4875787c28082690934 Mon Sep 17 00:00:00 2001 From: Aaron Louie Date: Wed, 12 Feb 2020 11:07:01 -0500 Subject: [PATCH] Fixes vulnerability identified by SonarCloud --- crc/scripts/CompleteTemplate.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/crc/scripts/CompleteTemplate.py b/crc/scripts/CompleteTemplate.py index 4086cc15..8ae33b97 100644 --- a/crc/scripts/CompleteTemplate.py +++ b/crc/scripts/CompleteTemplate.py @@ -56,7 +56,7 @@ class CompleteTemplate(object): def make_template(self, file_data_model, context): doc = DocxTemplate(BytesIO(file_data_model.data)) - jinja_env = jinja2.Environment() + jinja_env = jinja2.Environment(autoescape=True) doc.render(context, jinja_env) target_stream = BytesIO() doc.save(target_stream)