nmweb HTML injection

2022-08-22 Thread Jakub Wilk
See: https://nmbug.notmuchmail.org/nmweb/search/markup%20where%20appropriate and from the mail subject was dumped without escaping into HTML. -- Jakub Wilk ___ notmuch mailing list -- notmuch@notmuchmail.org To unsubscribe send an email to notmuch-le

Re: notmuch release 0.37 now available

2022-08-22 Thread erik colson
Awesome! Thank you! -- erik colson ___ notmuch mailing list -- notmuch@notmuchmail.org To unsubscribe send an email to notmuch-le...@notmuchmail.org

Re: nmweb HTML injection

2022-08-22 Thread Michael J Gruber
Am Mo., 22. Aug. 2022 um 09:22 Uhr schrieb Jakub Wilk : > > See: https://nmbug.notmuchmail.org/nmweb/search/markup%20where%20appropriate > > and from the mail subject was dumped without escaping into HTML. > Interesting :) The body is htmlescape()ed, but the subject header is used as is. I shou

Re: notmuch release 0.37 now available

2022-08-22 Thread Michael J Gruber
Thanks for another fine release, and for being a pleasant upstream to work with! For Fedora Linux/RHEL/etc folks: notmuch 0.37 is available in rawhide and f37 (branched), as well as in updates-testing for the current release f36, all with sfsexp support. It will not go to any EPEL branch (per guid