Skip to content

Commit 049c7e6

Browse files
dcramerclaude
andcommitted
fix(tools): escape backslash characters in markdown output
Address CodeQL security alert by escaping backslash characters before escaping other special markdown characters. This prevents incomplete escaping when input contains backslashes. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
1 parent 9021a97 commit 049c7e6

1 file changed

Lines changed: 2 additions & 1 deletion

File tree

‎packages/mcp-core/src/tools/get-issue-tag-values.ts‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -159,8 +159,9 @@ export default defineTool({
159159
value.value.length > 60
160160
? `${value.value.substring(0, 57)}...`
161161
: value.value;
162-
// Escape markdown table special characters
162+
// Escape markdown table special characters (backslashes first)
163163
displayValue = displayValue
164+
.replace(/\\/g, "\\\\")
164165
.replace(/\|/g, "\\|")
165166
.replace(/`/g, "\\`")
166167
.replace(/\n/g, " ");

0 commit comments

Comments
 (0)