mirror of
https://github.com/discourse/discourse.git
synced 2025-02-23 22:58:39 +08:00

If a theme name contained a double-quote, this problem could lead to invalid/unexpected HTML in the `<head>` Note that this is not considered a security issue because themes can only be installed/named by administrators, and themes/administrators already have the ability to run arbitrary javascript.