From 8a5ff921040581bb22145871715d1337a7ee1d7e Mon Sep 17 00:00:00 2001 From: mehbark Date: Thu, 11 Jul 2024 02:25:30 -0400 Subject: [PATCH] name-color: shore up one of the last vulns --- serverside/name-color.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/serverside/name-color.ts b/serverside/name-color.ts index 8b10093..321b53c 100644 --- a/serverside/name-color.ts +++ b/serverside/name-color.ts @@ -45,7 +45,7 @@ async function get_name_color(name: string): Promise { if (text.startsWith("name-color: ")) { const color = text.split("name-color: ")[1] .slice(0, MAX_COLOR_LEN) - .replaceAll(";", ""); + .replaceAll(/[;{}"']/g, ""); if (is_valid_color(color)) { return color; } else {